Direct Vulnerabilities

Known vulnerabilities in the tomcat package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

<1:9.0.120-1.el8_10
  • H
Authentication Bypass

<1:9.0.120-1.el8_10
  • H
Insufficient Logging

<1:9.0.120-1.el8_10
  • H
Detection of Error Condition Without Action

<1:9.0.120-1.el8_10
  • H
Improperly Implemented Security Check for Standard

<1:9.0.120-1.el8_10
  • H
Cross-site Scripting (XSS)

<1:9.0.120-1.el8_10
  • H
Information Exposure

<1:9.0.120-1.el8_10
  • H
Allocation of Resources Without Limits or Throttling

<1:9.0.120-1.el8_10
  • H
File and Directory Information Exposure

<1:9.0.120-1.el8_10
  • H
Inappropriate Encoding for Output Context

<1:9.0.120-1.el8_10
  • H
Incorrect Implementation of Authentication Algorithm

<1:9.0.120-1.el8_10
  • H
Open Redirect

<1:9.0.120-1.el8_10
  • H
HTTP Request Smuggling

<1:9.0.120-1.el8_10
  • H
Improper Input Validation

<1:9.0.120-1.el8_10
  • H
Improper Validation of Unsafe Equivalence in Input

<1:9.0.120-1.el8_10
  • H
Improper Resource Shutdown or Release

<1:9.0.120-1.el8_10
  • H
Improper Neutralization

<1:9.0.120-1.el8_10
  • H
Session Fixation

<1:9.0.120-1.el8_10
  • H
Improper Handling of Case Sensitivity

<1:9.0.120-1.el8_10
  • H
Resource Exhaustion

<1:9.0.120-1.el8_10
  • H
Uncaught Exception

<1:9.0.120-1.el8_10
  • H
Arbitrary Code Injection

<1:9.0.87-1.el8_10.1
  • H
Insecure Default Initialization of Resource

<1:9.0.120-1.el8_10
  • H
Reliance on Untrusted Inputs in a Security Decision

<1:9.0.120-1.el8_10
  • H
Authentication Bypass by Primary Weakness

<1:9.0.120-1.el8_10
  • H
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

<1:9.0.120-1.el8_10
  • H
Improper Handling of Case Sensitivity

<1:9.0.120-1.el8_10
  • H
Incorrect Implementation of Authentication Algorithm

<1:9.0.120-1.el8_10
  • H
Information Exposure

<1:9.0.120-1.el8_10
  • H
Improper Validation of Syntactic Correctness of Input

<1:9.0.120-1.el8_10
  • H
Reliance on Untrusted Inputs in a Security Decision

<1:9.0.87-2.el8_10
  • H
Use of a Risky Cryptographic Primitive

<1:9.0.87-2.el8_10
  • H
Directory Traversal

<1:9.0.87-1.el8_10.7
  • H
Improper Neutralization

<1:9.0.87-1.el8_10.7
  • H
Resource Exhaustion

<1:9.0.87-1.el8_10.6
  • H
Integer Overflow or Wraparound

<1:9.0.87-1.el8_10.6
  • H
Race Condition

<1:9.0.87-1.el8_10.6
  • H
Authentication Bypass

<1:9.0.87-1.el8_10.6
  • H
Resource Exhaustion

<1:9.0.87-1.el8_10.6
  • H
Allocation of Resources Without Limits or Throttling

<1:9.0.87-1.el8_10.6
  • H
Allocation of Resources Without Limits or Throttling

<1:9.0.87-1.el8_10.6
  • H
Improper Input Validation

<1:9.0.87-1.el8_10.4
  • H
Time-of-check Time-of-use (TOCTOU)

<1:9.0.87-1.el8_10.4
  • M
Path Equivalence

<1:9.0.87-1.el8_10.3
  • M
Time-of-check Time-of-use (TOCTOU)

<1:9.0.87-1.el8_10.3
  • H
Resource Exhaustion

<1:9.0.87-1.el8_10.2
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<1:9.0.87-1.el8_10.2
  • H
Improper Input Validation

<1:9.0.87-1.el8_10.1
  • H
Incomplete Cleanup

<1:9.0.87-1.el8_10.1
  • H
HTTP Request Smuggling

<1:9.0.62-27.el8_9.3
  • M
Improper Input Validation

<1:9.0.62-27.el8_9.2
  • M
Incomplete Cleanup

<1:9.0.62-27.el8_9.2
  • M
Incomplete Cleanup

<1:9.0.62-27.el8_9.2
  • M
Open Redirect

<1:9.0.62-27.el8_9.2
  • M
Off-by-one Error

<1:9.0.62-27.el8_9
  • M
Information Exposure

<1:9.0.62-27.el8_9
  • M
Allocation of Resources Without Limits or Throttling

<1:9.0.62-27.el8_9
  • H
Resource Exhaustion

<1:9.0.62-5.el8_8.2