Known vulnerabilities in tomcat-help - page 4

Vendor: openEuler
Software: tomcat-help
Software CPE: cpe:2.3:o:openeuler:tomcat-help:*:*:*:*:*:openeuler:*:*
Total vulnerabilities: 73
Public exploits: 15
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.2

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting tomcat-help tomcat-help is affected by 73 known vulnerabilities: 5 high, 54 medium, 14 low Critical High Medium Low

Vulnerabilities (73)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU80089 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2023-41080
CWE-601 Medium
Available
No
9.0.10-29 29.08.2023 SB2023082924
SB2023100565
SB2023101122
and 51 more
#VU73957 - Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
CVE-2023-28708
CWE-614 Low
No
No
9.0.10-28 22.03.2023 SB2023032237
SB2023032939
SB2023032945
and 53 more
#VU68859 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-42252
CWE-444 Medium
No
No
9.0.10-27 31.10.2022 SB2022103146
SB2022112324
SB2022112533
and 43 more
#VU60079 - Permissions, Privileges, and Access Controls
CVE-2022-23181
CWE-264 Low
No
No
9.0.10-25, 9.0.10-26 27.01.2022 SB2022012708
SB2022030854
SB2022041951
and 25 more
#VU57389 - Resource exhaustion
CVE-2021-42340
CWE-400 Medium
No
No
9.0.10-22 15.10.2021 SB2021101507
SB2021110507
SB2021111711
and 28 more
#VU56634 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2021-41079
CWE-835 Medium
No
No
9.0.10-21, 9.0.10-26 15.09.2021 SB2021091527
SB2021100721
SB2021101512
and 16 more
#VU55423 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2021-33037
CWE-444 Medium
No
No
9.0.10-19 29.07.2021 SB2021072907
SB2021080807
SB2021080808
and 30 more
#VU55417 - Improper Authentication
CVE-2021-30640
CWE-287 Medium
No
No
9.0.10-20 29.07.2021 SB2021072901
SB2021072902
SB2021081231
and 14 more
#VU51014 - Resource Management Errors
CVE-2021-25122
CWE-399 Medium
No
No
9.0.10-18 01.03.2021 SB2021030115
SB2021031619
SB2021032519
and 23 more
#VU51012 - Deserialization of Untrusted Data
CVE-2021-25329
CWE-502 Medium
No
No
9.0.10-18 01.03.2021 SB2021030115
SB2021031620
SB2021040723
and 16 more
#VU49570 - Exposure of sensitive information to an unauthorized actor
CVE-2021-24122
CWE-200 Medium
No
No
9.0.10-17 14.01.2021 SB2021011807
SB2021072821
SB2022012734
and 5 more
#VU29356 - Resource exhaustion
CVE-2020-9494
CWE-400 Medium
No
No
9.0.10-18 29.06.2020 SB2020062906
SB2021040723
SB2022040522
and 2 more
#VU28158 - Deserialization of Untrusted Data
CVE-2020-9484
CWE-502 High
Available
No
9.0.10-18, 9.0.10-25, 9.0.10-26 21.05.2020 SB2020052124
SB2020052501
SB2020053102
and 47 more


Showing elements 61 - 80 out of 73