tomcat-el-5.0-api

Direct Vulnerabilities

Known vulnerabilities in the tomcat-el-5.0-api package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Symbolic Name not Mapping to Correct Object

*
  • M
HTTP Request Smuggling

*
  • M
Insufficient Session Expiration

*
  • L
Time-of-check Time-of-use (TOCTOU)

*
  • H
Off-by-one Error

*
  • M
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

*
  • M
Authentication Bypass

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Authentication Bypass by Primary Weakness

*
  • H
Incomplete Cleanup

<1:10.1.36-1.el10_0
  • H
Resource Exhaustion

<1:10.1.36-1.el10_0
  • M
Open Redirect

<1:10.1.36-1.el10_0
  • M
Improper Input Validation

<1:10.1.36-1.el10_0
  • M
Incomplete Cleanup

<1:10.1.36-1.el10_0
  • H
Improper Input Validation

<1:10.1.36-1.el10_0
  • H
HTTP Request Smuggling

<1:10.1.36-1.el10_0
  • H
Improper Input Validation

<1:10.1.49-1.el10
  • M
Incorrect Implementation of Authentication Algorithm

<1:10.1.49-4.el10_2
  • H
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

*
  • H
Authentication Bypass by Primary Weakness

<1:10.1.49-1.el10
  • M
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

<1:10.1.49-4.el10_2
  • M
Information Exposure

<1:10.1.49-4.el10_2
  • M
Improper Handling of Case Sensitivity

<1:10.1.49-4.el10_2
  • M
Allocation of Resources Without Limits or Throttling

*
  • L
Insecure Default Initialization of Resource

*
  • L
Reliance on Untrusted Inputs in a Security Decision

*
  • M
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

*
  • M
Improper Validation of Syntactic Correctness of Input

<1:10.1.49-4.el10_2
  • L
Insufficient Logging

*
  • L
Detection of Error Condition Without Action

*
  • M
Authentication Bypass

*
  • M
Cross-site Scripting (XSS)

*
  • M
Improperly Implemented Security Check for Standard

*
  • L
Inappropriate Encoding for Output Context

*
  • H
Reliance on Untrusted Inputs in a Security Decision

<1:10.1.49-3.el10_2
  • L
HTTP Request Smuggling

*
  • L
File and Directory Information Exposure

*
  • M
Incomplete Blacklist

<1:10.1.49-4.el10_2
  • H
Use of a Risky Cryptographic Primitive

<1:10.1.49-3.el10_2
  • M
Incorrect Implementation of Authentication Algorithm

*
  • L
Open Redirect

*
  • M
Incorrect Implementation of Authentication Algorithm

*
  • M
Improper Validation of Unsafe Equivalence in Input

*
  • L
Improper Input Validation

*
  • H
Improper Certificate Validation

<1:10.1.49-1.el10_2.1
  • M
Time-of-check Time-of-use (TOCTOU)

<1:10.1.36-1.el10_0
  • H
Directory Traversal

<1:10.1.36-3.el10_1.1
  • M
Improper Resource Shutdown or Release

<1:10.1.36-3.el10_1.1
  • M
Improper Neutralization

<1:10.1.49-1.el10
  • M
Session Fixation

<1:10.1.49-1.el10
  • H
Resource Exhaustion

<1:10.1.36-1.el10_0.2
  • M
Improper Handling of Case Sensitivity

<1:10.1.49-1.el10
  • M
Allocation of Resources Without Limits or Throttling

<1:10.1.36-1.el10_0.2
  • L
Improper Neutralization

<1:10.1.36-3.el10_1.1
  • L
Authentication Bypass

<1:10.1.36-1.el10_0.2
  • M
Allocation of Resources Without Limits or Throttling

<1:10.1.36-1.el10_0.2
  • L
Integer Overflow or Wraparound

<1:10.1.36-1.el10_0.2
  • M
Resource Exhaustion

<1:10.1.36-1.el10_0.2
  • M
Path Equivalence

<1:10.1.36-1.el10_0
  • L
Uncaught Exception

<1:10.1.36-1.el10_0
  • L
Resource Exhaustion

<1:10.1.36-1.el10_0