tomcat9-jsp-2.3-api

Direct Vulnerabilities

Known vulnerabilities in the tomcat9-jsp-2.3-api package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Incorrect Implementation of Authentication Algorithm

*
  • L
Authentication Bypass by Primary Weakness

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Improper Certificate Validation

*
  • L
Improper Handling of Length Parameter Inconsistency

*
  • L
HTTP Request Smuggling

*
  • L
Incomplete Cleanup

*
  • L
Incorrect Synchronization

*
  • H
HTTP Request Smuggling

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Authentication Bypass

*
  • H
Excessive Platform Resource Consumption within a Loop

*
  • L
Symbolic Name not Mapping to Correct Object

*
  • M
HTTP Request Smuggling

*
  • M
Insufficient Session Expiration

*
  • L
Time-of-check Time-of-use (TOCTOU)

*
  • H
Off-by-one Error

*
  • M
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

*
  • M
Authentication Bypass

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Authentication Bypass by Primary Weakness

*
  • H
Resource Exhaustion

<1:9.0.110-2.el10_2
  • M
Time-of-check Time-of-use (TOCTOU)

<1:9.0.87-5.el10_0.1
  • L
Information Exposure

<1:9.0.120-1.el10_2
  • H
Allocation of Resources Without Limits or Throttling

<1:9.0.120-1.el10_2
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<1:9.0.110-2.el10_2
  • M
Incorrect Implementation of Authentication Algorithm

<1:9.0.120-1.el10_2
  • H
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

*
  • H
Authentication Bypass by Primary Weakness

<1:9.0.110-2.el10_2
  • M
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

<1:9.0.120-1.el10_2
  • M
Information Exposure

<1:9.0.120-1.el10_2
  • M
Improper Handling of Case Sensitivity

<1:9.0.120-1.el10_2
  • M
Allocation of Resources Without Limits or Throttling

*
  • L
Insecure Default Initialization of Resource

<1:9.0.120-1.el10_2
  • L
Reliance on Untrusted Inputs in a Security Decision

<1:9.0.120-1.el10_2
  • M
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

<1:9.0.120-1.el10_2
  • M
Improper Validation of Syntactic Correctness of Input

<1:9.0.120-1.el10_2
  • L
Insufficient Logging

<1:9.0.120-1.el10_2
  • L
Detection of Error Condition Without Action

<1:9.0.120-1.el10_2
  • M
Authentication Bypass

<1:9.0.120-1.el10_2
  • M
Cross-site Scripting (XSS)

<1:9.0.120-1.el10_2
  • M
Improperly Implemented Security Check for Standard

<1:9.0.120-1.el10_2
  • L
Inappropriate Encoding for Output Context

<1:9.0.117-1.el10_2
  • H
Reliance on Untrusted Inputs in a Security Decision

<1:9.0.117-2.el10_2
  • L
HTTP Request Smuggling

<1:9.0.117-1.el10_2
  • L
File and Directory Information Exposure

<1:9.0.117-1.el10_2
  • M
Incomplete Blacklist

<1:9.0.120-1.el10_2
  • H
Use of a Risky Cryptographic Primitive

<1:9.0.117-2.el10_2
  • M
Incorrect Implementation of Authentication Algorithm

<1:9.0.117-1.el10_2
  • L
Open Redirect

<1:9.0.117-1.el10_2
  • M
Incorrect Implementation of Authentication Algorithm

<1:9.0.117-1.el10_2
  • M
Improper Validation of Unsafe Equivalence in Input

<1:9.0.117-1.el10_2
  • L
Improper Input Validation

<1:9.0.117-1.el10_2
  • H
Improper Certificate Validation

<1:9.0.117-1.el10_2
  • H
Directory Traversal

<1:9.0.87-8.el10_1.1
  • M
Improper Resource Shutdown or Release

<1:9.0.110-2.el10_2
  • M
Improper Neutralization

<1:9.0.110-2.el10_2
  • M
Session Fixation

<1:9.0.110-2.el10_2
  • H
Resource Exhaustion

<1:9.0.87-5.el10_0.3
  • M
Improper Handling of Case Sensitivity

<1:9.0.110-2.el10_2
  • M
Allocation of Resources Without Limits or Throttling

<1:9.0.87-5.el10_0.3
  • L
Improper Neutralization

<1:9.0.87-8.el10_1.1
  • L
Authentication Bypass

<1:9.0.87-5.el10_0.3
  • M
Allocation of Resources Without Limits or Throttling

<1:9.0.87-5.el10_0.3
  • L
Integer Overflow or Wraparound

<1:9.0.87-5.el10_0.3
  • M
Resource Exhaustion

<1:9.0.87-5.el10_0.3
  • M
Race Condition

<1:9.0.87-5.el10_0.3
  • M
Time-of-check Time-of-use (TOCTOU)

<1:9.0.87-5.el10_0.1
  • H
Improper Input Validation

<1:9.0.87-5.el10_0.1
  • M
Path Equivalence

<1:9.0.87-5.el10_0