Known vulnerabilities in Apache Tomcat 9.0.61 - page 4

Software: Apache Tomcat
Version: 9.0.61
Software CPE: cpe:2.3:a:apache_foundation:apache_tomcat:*:*:*:*:*:*:*:*
Total vulnerabilities: 68
Public exploits: 17
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.2

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Apache Tomcat version 9.0.61 Apache Tomcat 9.0.61 is affected by 68 vulnerabilities: 1 critical, 4 high, 48 medium, 15 low Critical High Medium Low

Vulnerabilities (68)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU80089 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2023-41080
CWE-601 Medium
Public exploit available
No
8.5.93, 9.0.80, 10.1.13, 11.0.0-M11 29.08.2023 SB2023082924
SB2023100565
SB2023101122
and 51 more
#VU76417 - Allocation of Resources Without Limits or Throttling
CVE-2023-28709
CWE-770 Medium
No
No
8.5.88, 9.0.74, 10.1.8, 11.0.0-M5 22.05.2023 SB2023052235
SB2023053003
SB2023053052
and 35 more
#VU73957 - Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
CVE-2023-28708
CWE-614 Low
No
No
8.5.86, 9.0.72, 10.1.6, 11.0.0-M3 22.03.2023 SB2023032237
SB2023032939
SB2023032945
and 53 more
#VU72427 - Allocation of Resources Without Limits or Throttling
CVE-2023-24998
CWE-770 Medium
Public exploit available
No
8.5.85, 9.0.71, 10.1.5, 11.0.0-M3 20.02.2023 SB2023022046
SB2023022047
SB2023030917
and 202 more
#VU70666 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-45143
CWE-94 Medium
No
No
8.5.84, 9.0.69, 10.1.2 03.01.2023 SB2023010329
SB2023012516
SB2023012606
and 34 more
#VU68859 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-42252
CWE-444 Medium
No
No
8.5.83, 9.0.68, 10.0.27, 10.1.1 31.10.2022 SB2022103146
SB2022112324
SB2022112533
and 43 more
#VU64627 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-34305
CWE-79 Medium
Public exploit available
No
8.5.82, 9.0.65, 10.0.23, 10.1.0-M17 23.06.2022 SB2022062338
SB2022071177
SB2022071801
and 26 more
#VU63225 - Data Handling
CVE-2022-29885
CWE-19 Low
Public exploit available
No
8.5.79, 9.0.63, 10.0.21, 10.1.0-M15 16.05.2022 SB2022051612
SB2022072044
SB20220720107
and 19 more


Showing elements 61 - 80 out of 68