Known vulnerabilities in tomcat9 (Red Hat package)
Vendor:
Red Hat Inc.
Software:
tomcat9 (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:tomcat9_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
12
Public exploits:
6
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.2
Breakdown by Severity Chart
Vulnerabilities (12)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU117681 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2025-55752 |
CWE-22 | High | 9.0.87-5.el10_0.4 | 27.10.2025 |
SB2025102748 SB20251031122 SB20251031123 and 43 more |
||
| #VU114024 - Resource exhaustion CVE-2025-48989 |
CWE-400 | Medium | 9.0.87-5.el10_0.3 | 13.08.2025 |
SB2025081375 SB2025081376 SB20250820127 and 49 more |
||
| #VU112276 - Resource exhaustion CVE-2025-53506 |
CWE-400 | Medium | 9.0.87-5.el10_0.3 | 04.07.2025 |
SB20250704167 SB2025072535 SB2025072536 and 41 more |
||
| #VU112275 - Resource Management Errors CVE-2025-52520 |
CWE-399 | Medium | 9.0.87-5.el10_0.3 | 04.07.2025 |
SB20250704167 SB2025072535 SB2025072536 and 42 more |
||
| #VU112274 - Improper input validation CVE-2025-52434 |
CWE-20 | Medium | 9.0.87-5.el10_0.3 | 04.07.2025 |
SB20250704167 SB2025072535 SB2025072536 and 32 more |
||
| #VU111162 - Resource exhaustion CVE-2025-48976 |
CWE-400 | Medium | 9.0.87-5.el10_0.3 | 16.06.2025 |
SB2025061634 SB2025061635 SB2025061927 and 156 more |
||
| #VU111161 - Resource exhaustion CVE-2025-48988 |
CWE-400 | Medium | 9.0.87-5.el10_0.3 | 16.06.2025 |
SB2025061634 SB2025061927 SB20250620145 and 40 more |
||
| #VU111159 - Improper Protection of Alternate Path CVE-2025-49125 |
CWE-424 | Medium | 9.0.87-5.el10_0.3 | 16.06.2025 |
SB2025061634 SB2025061927 SB20250620145 and 35 more |
||
| #VU107996 - Error Handling CVE-2025-31650 |
CWE-388 | Medium | 9.0.87-5.el10_0.1 | 28.04.2025 |
SB2025042851 SB2025050943 SB2025050982 and 38 more |
||
| #VU107995 - Improper input validation CVE-2025-31651 |
CWE-20 | Medium | 9.0.87-5.el10_0.4 | 28.04.2025 |
SB2025042851 SB2025050943 SB2025050982 and 46 more |
||
| #VU101893 - Permissions, Privileges, and Access Controls CVE-2024-56337 |
CWE-264 | High | 9.0.87-5.el10_0.1 | 20.12.2024 |
SB2024122063 SB2025011311 SB2025011801 and 45 more |
||
| #VU101814 - Permissions, Privileges, and Access Controls CVE-2024-50379 |
CWE-264 | Medium | 9.0.87-5.el10_0.1 | 17.12.2024 |
SB2024121745 SB2024121905 SB2024122055 and 57 more |