Known vulnerabilities in tomcat (Red Hat package) - page 2
Vendor:
Red Hat Inc.
Software:
tomcat (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:tomcat_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
30
Public exploits:
13
Known exploited (KEV):
4
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
7.0.76-18.el7_9
9.0.87-2.el8_8
9.0.117-2.el9_8
9.0.87-2.el9_2
9.0.87-4.el9_6
9.0.87-2.el9_4
9.0.117-1.el9_8
10.1.36-1.el10_0.3
9.0.87-1.el8_10.7
9.0.87-1.el9_4.7
9.0.87-1.el9_2.7
9.0.87-1.el8_8.8
9.0.87-1.el9_2.6
9.0.87-1.el8_8.7
9.0.87-3.el9_6.3
10.1.36-1.el10_0.2
9.0.87-1.el8_10.6
9.0.87-1.el8_8.5
9.0.87-1.el9_2.4
9.0.87-3.el9_6.1
9.0.87-1.el9_4.4
9.0.87-1.el8_10.4
9.0.87-1.el8_8.4
9.0.87-1.el8_10.3
9.0.87-1.el9_4.3
9.0.87-1.el9_2.3
9.0.87-2.el9_5.1
9.0.87-1.el9_2.2
9.0.87-1.el8_8.3
9.0.87-1.el8_10.2
9.0.87-1.el9_4.2
9.0.87-1.el8_8.2
9.0.87-1.el8_10.1
9.0.87-1.el9_2.1
9.0.87-1.el9_4.1
9.0.62-11.el9_2.4
9.0.62-37.el9_3.2
9.0.62-27.el8_9.3
9.0.62-5.el8_8.3
9.0.62-27.el8_9
9.0.62-37.el9_3
9.0.62-5.el8_8.2
9.0.62-11.el9_2.3
7.0.76-12.el7_8
7.0.76-12.el7_7
7.0.76-11.el7_6
7.0.76-16.el7_9
7.0.76-15.el7
7.0.76-10.el7_6
7.0.76-11.el7_7
7.0.76-9.el7
7.0.76-9.el7_6
7.0.76-8.el7_5
7.0.76-3.el7_4
7.0.76-2.el7
7.0.69-12.el7_3
7.0.42-5.el7_0
7.0.42-6.el7_0
7.0.42-8.el7_0
7.0.54-2.el7_1
7.0.54-8.el7_2
7.0.69-10.el7
7.0.69-11.el7_3
Vulnerabilities (30)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU83533 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2023-46589 |
CWE-444 | Medium | 9.0.62-5.el8_8.3, 9.0.62-11.el9_2.4, 9.0.62-27.el8_9.3, 9.0.62-37.el9_3.2 | 28.11.2023 |
SB2023112846 SB2023121851 SB2023122831 and 78 more |
||
| #VU81728 - Resource exhaustion CVE-2023-44487 |
CWE-400 | High | 9.0.62-5.el8_8.2, 9.0.62-11.el9_2.3 | 10.10.2023 |
SB2023101023 SB2023101024 SB2023101037 and 650 more |
||
| #VU76417 - Allocation of Resources Without Limits or Throttling CVE-2023-28709 |
CWE-770 | Medium | 9.0.62-27.el8_9, 9.0.62-37.el9_3 | 22.05.2023 |
SB2023052235 SB2023053003 SB2023053052 and 35 more |
||
| #VU73957 - Sensitive Cookie in HTTPS Session Without 'Secure' Attribute CVE-2023-28708 |
CWE-614 | Low | 9.0.62-27.el8_9, 9.0.62-37.el9_3 | 22.03.2023 |
SB2023032237 SB2023032939 SB2023032945 and 53 more |
||
| #VU72427 - Allocation of Resources Without Limits or Throttling CVE-2023-24998 |
CWE-770 | Medium | 9.0.62-27.el8_9, 9.0.62-37.el9_3 | 20.02.2023 |
SB2023022046 SB2023022047 SB2023030917 and 202 more |
||
| #VU29723 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2020-13935 |
CWE-835 | Medium | 7.0.76-15.el7 | 14.07.2020 |
SB2020071406 SB2020072801 SB2020072921 and 14 more |
||
| #VU28158 - Deserialization of Untrusted Data CVE-2020-9484 |
CWE-502 | High | 7.0.76-12.el7_8 | 21.05.2020 |
SB2020052124 SB2020052501 SB2020053102 and 47 more |
||
| #VU25807 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2020-1935 |
CWE-444 | Medium | 7.0.76-11.el7_6, 7.0.76-12.el7_7, 7.0.76-16.el7_9 | 06.03.2020 |
SB2020022111 SB2020031401 SB2020031402 and 15 more |
||
| #VU25502 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2020-1938 |
CWE-22 | High | 7.0.76-10.el7_6, 7.0.76-11.el7_7 | 21.02.2020 |
SB2020022111 SB2020031401 SB2020031402 and 31 more |
||
| #VU25002 - Session Fixation CVE-2019-17563 |
CWE-384 | Low | 7.0.76-11.el7_6, 7.0.76-12.el7_7, 7.0.76-15.el7 | 06.02.2020 |
SB2019121315 SB2020011492 SB2020011519 and 16 more |
Showing elements 21 - 40 out of 30