Known vulnerabilities in tomcat-jsp-2_3-api - page 3
Vendor:
SUSE
Software:
tomcat-jsp-2_3-api
Software CPE:
cpe:2.3:o:suse:tomcat-jsp-2_3-api:*:*:*:*:*:suse_linux:*:*
Website:
https://www.suse.com/
Total vulnerabilities:
69
Public exploits:
13
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.2
Breakdown by Severity Chart
9.0.120-3.174.1
9.0.120-150200.114.1
9.0.119-3.169.1
9.0.119-150200.111.1
9.0.118-150200.108.1
9.0.118-3.166.1
9.0.117-150200.105.1
9.0.117-3.163.2
9.0.115-3.160.1
9.0.115-150200.102.1
9.0.36-3.156.1
9.0.111-150200.99.1
9.0.36-3.153.2
9.0.111-150200.96.1
9.0.108-150200.91.1
9.0.36-3.148.1
9.0.36-3.142.1
9.0.104-150200.81.1
9.0.102-150200.78.1
9.0.36-3.139.1
9.0.36-3.136.1
9.0.98-150200.74.1
9.0.97-150200.71.1
9.0.36-3.133.1
9.0.36-3.130.1
9.0.36-3.127.1
9.0.91-150200.68.1
9.0.36-3.124.1
9.0.85-150200.57.1
9.0.36-3.118.1
9.0.36-150100.4.105.1
9.0.36-150100.4.98.1
9.0.36-3.111.1
9.0.82-150200.46.1
9.0.36-3.108.1
9.0.36-150100.4.93.1
9.0.75-150200.41.1
9.0.36-3.105.1
8.0.53-29.66.1
9.0.43-150200.38.1
9.0.43-150200.35.1
9.0.36-3.102.1
9.0.36-150100.4.90.1
9.0.36-150200.22.1
8.0.53-29.54.1
9.0.36-150100.4.76.1
9.0.36-150000.3.96.1
9.0.36-3.87.1
9.0.36-4.70.1
8.0.53-29.46.1
9.0.36-3.79.1
9.0.36-3.64.1
8.0.53-29.63.1
9.0.36-3.99.1
9.0.36-150100.4.87.1
9.0.36-3.93.1
9.0.36-150100.4.81.1
9.0.36-150000.3.101.2
8.0.53-29.57.1
9.0.36-3.90.1
9.0.36-13.1
9.0.36-3.84.1
9.0.36-4.63.1
9.0.36-3.71.1
9.0.36-4.58.1
9.0.36-3.24.1
Vulnerabilities (69)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU101814 - Permissions, Privileges, and Access Controls CVE-2024-50379 |
CWE-264 | Medium | 9.0.36-3.136.1, 9.0.98-150200.74.1 | 17.12.2024 |
SB2024121745 SB2024121905 SB2024122055 and 57 more |
||
| #VU101813 - Resource exhaustion CVE-2024-54677 |
CWE-400 | Medium | 9.0.36-3.136.1, 9.0.98-150200.74.1 | 17.12.2024 |
SB2024121745 SB2024121905 SB2024122055 and 13 more |
||
| #VU100588 - Improper Authentication CVE-2024-52316 |
CWE-287 | Low | 9.0.36-3.133.1, 9.0.97-150200.71.1 | 18.11.2024 |
SB2024111823 SB2024112550 SB2024112832 and 36 more |
||
| #VU100587 - Resource Management Errors CVE-2024-52317 |
CWE-399 | Medium | 9.0.98-150200.74.1 | 18.11.2024 |
SB2024111823 SB2024112550 SB2024121231 and 27 more |
||
| #VU97652 - Resource exhaustion CVE-2024-38286 |
CWE-400 | Medium | 9.0.36-3.130.1 | 23.09.2024 |
SB2024092355 SB2024100267 SB2024102808 and 26 more |
||
| #VU93732 - Resource Management Errors CVE-2024-34750 |
CWE-399 | Medium | 9.0.36-3.127.1, 9.0.91-150200.68.1 | 03.07.2024 |
SB2024070346 SB20240711245 SB2024071542 and 56 more |
||
| #VU87510 - Improper input validation CVE-2024-24549 |
CWE-20 | Medium | 9.0.36-3.124.1 | 13.03.2024 |
SB2024031386 SB2024031879 SB2024031880 and 64 more |
||
| #VU87509 - Resource exhaustion CVE-2024-23672 |
CWE-400 | Medium | 9.0.36-3.124.1 | 13.03.2024 |
SB2024031386 SB2024032821 SB2024032824 and 49 more |
||
| #VU86574 - Incorrect Default Permissions CVE-2024-22029 |
CWE-276 | Low | 9.0.85-150200.57.1 | 19.02.2024 |
SB2024021927 SB2024021928 |
||
| #VU83533 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2023-46589 |
CWE-444 | Medium | 9.0.36-3.118.1, 9.0.36-150100.4.105.1, 9.0.85-150200.57.1 | 28.11.2023 |
SB2023112846 SB2023121851 SB2023122831 and 78 more |
||
| #VU81803 - Exposed Dangerous Method or Function CVE-2023-42794 |
CWE-749 | Medium | 9.0.85-150200.57.1 | 10.10.2023 |
SB2023101084 SB2023101286 SB2023111528 and 22 more |
||
| #VU81800 - Resource Management Errors CVE-2023-42795 |
CWE-399 | Medium | 9.0.36-3.111.1, 9.0.36-150100.4.98.1, 9.0.85-150200.57.1 | 10.10.2023 |
SB2023101084 SB2023101122 SB2023101123 and 47 more |
||
| #VU81799 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2023-45648 |
CWE-444 | Medium | 9.0.36-3.111.1, 9.0.36-150100.4.98.1, 9.0.85-150200.57.1 | 10.10.2023 |
SB2023101084 SB2023101122 SB2023101123 and 47 more |
||
| #VU81728 - Resource exhaustion CVE-2023-44487 |
CWE-400 | High | 9.0.82-150200.46.1 | 10.10.2023 |
SB2023101023 SB2023101024 SB2023101037 and 650 more |
||
| #VU80089 - URL Redirection to Untrusted Site ('Open Redirect') CVE-2023-41080 |
CWE-601 | Medium | 9.0.36-3.108.1, 9.0.36-150100.4.98.1, 9.0.82-150200.46.1 | 29.08.2023 |
SB2023082924 SB2023100565 SB2023101122 and 51 more |
||
| #VU76417 - Allocation of Resources Without Limits or Throttling CVE-2023-28709 |
CWE-770 | Medium | 8.0.53-29.66.1, 9.0.36-3.105.1, 9.0.36-150100.4.93.1, 9.0.75-150200.41.1 | 22.05.2023 |
SB2023052235 SB2023053003 SB2023053052 and 35 more |
||
| #VU73957 - Sensitive Cookie in HTTPS Session Without 'Secure' Attribute CVE-2023-28708 |
CWE-614 | Low | 9.0.36-3.102.1, 9.0.36-150100.4.90.1, 9.0.43-150200.35.1 | 22.03.2023 |
SB2023032237 SB2023032939 SB2023032945 and 53 more |
||
| #VU72427 - Allocation of Resources Without Limits or Throttling CVE-2023-24998 |
CWE-770 | Medium | 8.0.53-29.63.1, 8.0.53-29.66.1, 9.0.36-3.99.1, 9.0.36-3.105.1, 9.0.36-150100.4.87.1, 9.0.36-150100.4.93.1, 9.0.43-150200.35.1, 9.0.75-150200.41.1 | 20.02.2023 |
SB2023022046 SB2023022047 SB2023030917 and 202 more |
||
| #VU70666 - Improper Control of Generation of Code ('Code Injection') CVE-2022-45143 |
CWE-94 | Medium | 9.0.43-150200.38.1 | 03.01.2023 |
SB2023010329 SB2023012516 SB2023012606 and 34 more |
||
| #VU68859 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2022-42252 |
CWE-444 | Medium | 8.0.53-29.57.1, 9.0.36-3.93.1, 9.0.36-150000.3.101.2, 9.0.36-150100.4.81.1 | 31.10.2022 |
SB2022103146 SB2022112324 SB2022112533 and 43 more |
Showing elements 41 - 60 out of 69