Known vulnerabilities in tomcat-jsp-2_3-api
Vendor:
SUSE
Software:
tomcat-jsp-2_3-api
Software CPE:
cpe:2.3:o:suse:tomcat-jsp-2_3-api:*:*:*:*:*:suse_linux:*:*
Website:
https://www.suse.com/
Total vulnerabilities:
69
Public exploits:
13
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.2
Breakdown by Severity Chart
9.0.120-3.174.1
9.0.120-150200.114.1
9.0.119-3.169.1
9.0.119-150200.111.1
9.0.118-150200.108.1
9.0.118-3.166.1
9.0.117-150200.105.1
9.0.117-3.163.2
9.0.115-3.160.1
9.0.115-150200.102.1
9.0.36-3.156.1
9.0.111-150200.99.1
9.0.36-3.153.2
9.0.111-150200.96.1
9.0.108-150200.91.1
9.0.36-3.148.1
9.0.36-3.142.1
9.0.104-150200.81.1
9.0.102-150200.78.1
9.0.36-3.139.1
9.0.36-3.136.1
9.0.98-150200.74.1
9.0.97-150200.71.1
9.0.36-3.133.1
9.0.36-3.130.1
9.0.36-3.127.1
9.0.91-150200.68.1
9.0.36-3.124.1
9.0.85-150200.57.1
9.0.36-3.118.1
9.0.36-150100.4.105.1
9.0.36-150100.4.98.1
9.0.36-3.111.1
9.0.82-150200.46.1
9.0.36-3.108.1
9.0.36-150100.4.93.1
9.0.75-150200.41.1
9.0.36-3.105.1
8.0.53-29.66.1
9.0.43-150200.38.1
9.0.43-150200.35.1
9.0.36-3.102.1
9.0.36-150100.4.90.1
9.0.36-150200.22.1
8.0.53-29.54.1
9.0.36-150100.4.76.1
9.0.36-150000.3.96.1
9.0.36-3.87.1
9.0.36-4.70.1
8.0.53-29.46.1
9.0.36-3.79.1
9.0.36-3.64.1
8.0.53-29.63.1
9.0.36-3.99.1
9.0.36-150100.4.87.1
9.0.36-3.93.1
9.0.36-150100.4.81.1
9.0.36-150000.3.101.2
8.0.53-29.57.1
9.0.36-3.90.1
9.0.36-13.1
9.0.36-3.84.1
9.0.36-4.63.1
9.0.36-3.71.1
9.0.36-4.58.1
9.0.36-3.24.1
Vulnerabilities (69)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU137407 - Insufficient Technical Documentation CVE-2026-59084 |
CWE-1059 | Low | 9.0.120-3.174.1, 9.0.120-150200.114.1 | 14.07.2026 |
SB2026071451 SB2026072515 SB2026073050 and 4 more |
||
| #VU137408 - Incorrect Behavior Order: Validate Before Canonicalize CVE-2026-59083 |
CWE-180 | Medium | 9.0.120-3.174.1, 9.0.120-150200.114.1 | 14.07.2026 |
SB2026071451 SB2026072515 SB2026073050 and 4 more |
||
| #VU135862 - Improper Access Control CVE-2026-55956 |
CWE-284 | Medium | 9.0.119-3.169.1, 9.0.119-150200.111.1 | 30.06.2026 |
SB2026063007 SB2026070957 SB2026070958 and 7 more |
||
| #VU135863 - Authentication Bypass by Capture-replay CVE-2026-55955 |
CWE-294 | Medium | 9.0.119-3.169.1, 9.0.119-150200.111.1 | 30.06.2026 |
SB2026063007 SB2026070957 SB2026070958 and 6 more |
||
| #VU135864 - Always-Incorrect Control Flow Implementation CVE-2026-55276 |
CWE-670 | Low | 9.0.119-3.169.1, 9.0.119-150200.111.1 | 30.06.2026 |
SB2026063007 SB2026070957 SB2026070958 and 7 more |
||
| #VU135865 - Improper Certificate Validation CVE-2026-53434 |
CWE-295 | Medium | 9.0.119-3.169.1, 9.0.119-150200.111.1 | 30.06.2026 |
SB2026063007 SB2026070957 SB2026070958 and 7 more |
||
| #VU135866 - Always-Incorrect Control Flow Implementation CVE-2026-53404 |
CWE-670 | Medium | 9.0.119-3.169.1, 9.0.119-150200.111.1 | 30.06.2026 |
SB2026063007 SB2026070957 SB2026070958 and 8 more |
||
| #VU135867 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2026-50229 |
CWE-79 | Low | 9.0.119-3.169.1, 9.0.119-150200.111.1 | 30.06.2026 |
SB2026063007 SB2026070957 SB2026070958 and 8 more |
||
| #VU131177 - Improper Access Control CVE-2026-43515 |
CWE-284 | Medium | 9.0.118-3.166.1, 9.0.118-150200.108.1 | 12.05.2026 |
SB2026051281 SB2026051592 SB2026060605 and 21 more |
||
| #VU131178 - Information Exposure Through Timing Discrepancy CVE-2026-43514 |
CWE-208 | Low | 9.0.118-3.166.1, 9.0.118-150200.108.1 | 12.05.2026 |
SB2026051281 SB2026051592 SB2026060851 and 13 more |
||
| #VU131179 - Improper Handling of Case Sensitivity CVE-2026-43513 |
CWE-178 | Medium | 9.0.118-3.166.1, 9.0.118-150200.108.1 | 12.05.2026 |
SB2026051281 SB2026051592 SB2026060605 and 19 more |
||
| #VU131180 - Improper Authentication CVE-2026-43512 |
CWE-287 | Medium | 9.0.118-3.166.1, 9.0.118-150200.108.1 | 12.05.2026 |
SB2026051281 SB2026051592 SB2026052607 and 21 more |
||
| #VU131181 - Exposure of sensitive information to an unauthorized actor CVE-2026-42498 |
CWE-200 | Low | 9.0.118-3.166.1, 9.0.118-150200.108.1 | 12.05.2026 |
SB2026051281 SB2026051592 SB2026052607 and 18 more |
||
| #VU131182 - Improper input validation CVE-2026-41293 |
CWE-20 | Medium | 9.0.118-3.166.1, 9.0.118-150200.108.1 | 12.05.2026 |
SB2026051281 SB2026051592 SB2026052607 and 21 more |
||
| #VU131183 - Resource exhaustion CVE-2026-41284 |
CWE-400 | Medium | 9.0.118-3.166.1, 9.0.118-150200.108.1 | 12.05.2026 |
SB2026051281 SB2026051592 SB2026052607 and 21 more |
||
| #VU125743 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2026-24880 |
CWE-444 | Medium | 9.0.117-3.163.2, 9.0.117-150200.105.1 | 09.04.2026 |
SB20260409109 SB20260417131 SB20260422214 and 18 more |
||
| #VU125740 - Improper Certificate Validation CVE-2026-29145 |
CWE-295 | Low | 9.0.117-3.163.2, 9.0.117-150200.105.1 | 09.04.2026 |
SB20260409109 SB20260417131 SB20260422214 and 17 more |
||
| #VU125741 - Configuration CVE-2026-29129 |
CWE-16 | Medium | 9.0.117-3.163.2, 9.0.117-150200.105.1 | 09.04.2026 |
SB20260409109 SB20260417131 SB20260422214 and 12 more |
||
| #VU125742 - URL Redirection to Untrusted Site ('Open Redirect') CVE-2026-25854 |
CWE-601 | Low | 9.0.117-3.163.2, 9.0.117-150200.105.1 | 09.04.2026 |
SB20260409109 SB2026041565 SB20260417131 and 14 more |
||
| #VU125738 - Improper input validation CVE-2026-32990 |
CWE-20 | Medium | 9.0.117-3.163.2, 9.0.117-150200.105.1 | 09.04.2026 |
SB20260409109 SB20260417131 SB2026042329 and 9 more |
Showing elements 1 - 20 out of 69