Known vulnerabilities in tomcat (Red Hat package) - page 2

Software CPE: cpe:2.3:o:red_hat:tomcat_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 30
Public exploits: 13
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting tomcat (Red Hat package) tomcat (Red Hat package) is affected by 30 known vulnerabilities: 1 critical, 5 high, 22 medium, 2 low Critical High Medium Low

Vulnerabilities (30)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU83533 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2023-46589
CWE-444 Medium
No
No
9.0.62-5.el8_8.3, 9.0.62-11.el9_2.4, 9.0.62-27.el8_9.3, 9.0.62-37.el9_3.2 28.11.2023 SB2023112846
SB2023121851
SB2023122831
and 78 more
#VU81728 - Resource exhaustion
CVE-2023-44487
CWE-400 High
Available
Exploited
9.0.62-5.el8_8.2, 9.0.62-11.el9_2.3 10.10.2023 SB2023101023
SB2023101024
SB2023101037
and 650 more
#VU76417 - Allocation of Resources Without Limits or Throttling
CVE-2023-28709
CWE-770 Medium
No
No
9.0.62-27.el8_9, 9.0.62-37.el9_3 22.05.2023 SB2023052235
SB2023053003
SB2023053052
and 35 more
#VU73957 - Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
CVE-2023-28708
CWE-614 Low
No
No
9.0.62-27.el8_9, 9.0.62-37.el9_3 22.03.2023 SB2023032237
SB2023032939
SB2023032945
and 53 more
#VU72427 - Allocation of Resources Without Limits or Throttling
CVE-2023-24998
CWE-770 Medium
Available
No
9.0.62-27.el8_9, 9.0.62-37.el9_3 20.02.2023 SB2023022046
SB2023022047
SB2023030917
and 202 more
#VU29723 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2020-13935
CWE-835 Medium
Available
No
7.0.76-15.el7 14.07.2020 SB2020071406
SB2020072801
SB2020072921
and 14 more
#VU28158 - Deserialization of Untrusted Data
CVE-2020-9484
CWE-502 High
Available
No
7.0.76-12.el7_8 21.05.2020 SB2020052124
SB2020052501
SB2020053102
and 47 more
#VU25807 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2020-1935
CWE-444 Medium
No
No
7.0.76-11.el7_6, 7.0.76-12.el7_7, 7.0.76-16.el7_9 06.03.2020 SB2020022111
SB2020031401
SB2020031402
and 15 more
#VU25502 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2020-1938
CWE-22 High
Available
Exploited
7.0.76-10.el7_6, 7.0.76-11.el7_7 21.02.2020 SB2020022111
SB2020031401
SB2020031402
and 31 more
#VU25002 - Session Fixation
CVE-2019-17563
CWE-384 Low
No
No
7.0.76-11.el7_6, 7.0.76-12.el7_7, 7.0.76-15.el7 06.02.2020 SB2019121315
SB2020011492
SB2020011519
and 16 more


Showing elements 21 - 40 out of 30