tomcat-lib

Direct Vulnerabilities

Known vulnerabilities in the tomcat-lib package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

<1:9.0.120-1.el8_10
  • H
Authentication Bypass

<1:9.0.120-1.el8_10
  • H
Insufficient Logging

<1:9.0.120-1.el8_10
  • H
Detection of Error Condition Without Action

<1:9.0.120-1.el8_10
  • H
Improperly Implemented Security Check for Standard

<1:9.0.120-1.el8_10
  • H
Cross-site Scripting (XSS)

<1:9.0.120-1.el8_10
  • H
Information Exposure

<1:9.0.120-1.el8_10
  • H
Allocation of Resources Without Limits or Throttling

<1:9.0.120-1.el8_10
  • H
File and Directory Information Exposure

<1:9.0.120-1.el8_10
  • H
Inappropriate Encoding for Output Context

<1:9.0.120-1.el8_10
  • H
Incorrect Implementation of Authentication Algorithm

<1:9.0.120-1.el8_10
  • H
Open Redirect

<1:9.0.120-1.el8_10
  • H
HTTP Request Smuggling

<1:9.0.120-1.el8_10
  • H
Improper Input Validation

<1:9.0.120-1.el8_10
  • H
Improper Validation of Unsafe Equivalence in Input

<1:9.0.120-1.el8_10
  • H
Improper Resource Shutdown or Release

<1:9.0.120-1.el8_10
  • H
Improper Neutralization

<1:9.0.120-1.el8_10
  • H
Session Fixation

<1:9.0.120-1.el8_10
  • H
Improper Handling of Case Sensitivity

<1:9.0.120-1.el8_10
  • H
Resource Exhaustion

<1:9.0.120-1.el8_10
  • H
Uncaught Exception

<1:9.0.120-1.el8_10
  • H
Arbitrary Code Injection

<1:9.0.87-1.el8_10.1
  • H
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

<1:9.0.120-1.el8_8
  • H
Authentication Bypass

<1:9.0.120-1.el8_8
  • H
Insufficient Logging

<1:9.0.120-1.el8_8
  • H
Detection of Error Condition Without Action

<1:9.0.120-1.el8_8
  • H
Improperly Implemented Security Check for Standard

<1:9.0.120-1.el8_8
  • H
Cross-site Scripting (XSS)

<1:9.0.120-1.el8_8
  • H
Information Exposure

<1:9.0.120-1.el8_8
  • H
Allocation of Resources Without Limits or Throttling

<1:9.0.120-1.el8_8
  • H
File and Directory Information Exposure

<1:9.0.120-1.el8_8
  • H
Inappropriate Encoding for Output Context

<1:9.0.120-1.el8_8
  • H
Incorrect Implementation of Authentication Algorithm

<1:9.0.120-1.el8_8
  • H
Open Redirect

<1:9.0.120-1.el8_8
  • H
HTTP Request Smuggling

<1:9.0.120-1.el8_8
  • H
Improper Input Validation

<1:9.0.120-1.el8_8
  • H
Improper Validation of Unsafe Equivalence in Input

<1:9.0.120-1.el8_8
  • H
Improper Resource Shutdown or Release

<1:9.0.120-1.el8_8
  • H
Improper Neutralization

<1:9.0.120-1.el8_8
  • H
Session Fixation

<1:9.0.120-1.el8_8
  • H
Improper Handling of Case Sensitivity

<1:9.0.120-1.el8_8
  • H
Resource Exhaustion

<1:9.0.120-1.el8_8
  • H
Uncaught Exception

<1:9.0.120-1.el8_8
  • H
Improper Input Validation

<1:9.0.87-1.el8_8.2
  • H
Incomplete Cleanup

<1:9.0.87-1.el8_8.2
  • H
Open Redirect

<1:9.0.87-1.el8_8.2
  • H
Information Exposure

<1:9.0.87-1.el8_8.2
  • H
Allocation of Resources Without Limits or Throttling

<1:9.0.87-1.el8_8.2
  • H
Arbitrary Code Injection

<1:9.0.87-1.el8_8.2
  • H
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

<1:9.0.120-1.el8_8
  • H
Authentication Bypass

<1:9.0.120-1.el8_8
  • H
Insufficient Logging

<1:9.0.120-1.el8_8
  • H
Detection of Error Condition Without Action

<1:9.0.120-1.el8_8
  • H
Improperly Implemented Security Check for Standard

<1:9.0.120-1.el8_8
  • H
Cross-site Scripting (XSS)

<1:9.0.120-1.el8_8
  • H
Information Exposure

<1:9.0.120-1.el8_8
  • H
Allocation of Resources Without Limits or Throttling

<1:9.0.120-1.el8_8
  • H
File and Directory Information Exposure

<1:9.0.120-1.el8_8
  • H
Inappropriate Encoding for Output Context

<1:9.0.120-1.el8_8
  • H
Incorrect Implementation of Authentication Algorithm

<1:9.0.120-1.el8_8
  • H
Open Redirect

<1:9.0.120-1.el8_8
  • H
HTTP Request Smuggling

<1:9.0.120-1.el8_8
  • H
Improper Input Validation

<1:9.0.120-1.el8_8
  • H
Improper Validation of Unsafe Equivalence in Input

<1:9.0.120-1.el8_8
  • H
Improper Resource Shutdown or Release

<1:9.0.120-1.el8_8
  • H
Improper Neutralization

<1:9.0.120-1.el8_8
  • H
Session Fixation

<1:9.0.120-1.el8_8
  • H
Improper Handling of Case Sensitivity

<1:9.0.120-1.el8_8
  • H
Resource Exhaustion

<1:9.0.120-1.el8_8
  • H
Uncaught Exception

<1:9.0.120-1.el8_8
  • H
Improper Input Validation

<1:9.0.87-1.el8_8.2
  • H
Incomplete Cleanup

<1:9.0.87-1.el8_8.2
  • H
Open Redirect

<1:9.0.87-1.el8_8.2
  • H
Information Exposure

<1:9.0.87-1.el8_8.2
  • H
Allocation of Resources Without Limits or Throttling

<1:9.0.87-1.el8_8.2
  • H
Arbitrary Code Injection

<1:9.0.87-1.el8_8.2
  • H
Improper Input Validation

<1:9.0.87-1.el8_8.2
  • H
Incomplete Cleanup

<1:9.0.87-1.el8_8.2
  • H
Open Redirect

<1:9.0.87-1.el8_8.2
  • H
Information Exposure

<1:9.0.87-1.el8_8.2
  • H
Allocation of Resources Without Limits or Throttling

<1:9.0.87-1.el8_8.2
  • H
Arbitrary Code Injection

<1:9.0.87-1.el8_8.2
  • H
Improper Input Validation

<1:9.0.87-1.el8_8.2
  • H
Incomplete Cleanup

<1:9.0.87-1.el8_8.2
  • H
Open Redirect

<1:9.0.87-1.el8_8.2
  • H
Information Exposure

<1:9.0.87-1.el8_8.2
  • H
Allocation of Resources Without Limits or Throttling

<1:9.0.87-1.el8_8.2
  • H
Arbitrary Code Injection

<1:9.0.87-1.el8_8.2
  • H
Insecure Default Initialization of Resource

<1:9.0.120-1.el8_10
  • H
Reliance on Untrusted Inputs in a Security Decision

<1:9.0.120-1.el8_10
  • H
Authentication Bypass by Primary Weakness

<1:9.0.120-1.el8_10
  • H
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

<1:9.0.120-1.el8_10
  • H
Improper Handling of Case Sensitivity

<1:9.0.120-1.el8_10
  • H
Incorrect Implementation of Authentication Algorithm

<1:9.0.120-1.el8_10
  • H
Information Exposure

<1:9.0.120-1.el8_10
  • H
Improper Validation of Syntactic Correctness of Input

<1:9.0.120-1.el8_10
  • H
Insecure Default Initialization of Resource

<1:9.0.120-1.el8_8
  • H
Reliance on Untrusted Inputs in a Security Decision

<1:9.0.120-1.el8_8
  • H
Authentication Bypass by Primary Weakness

<1:9.0.120-1.el8_8
  • H
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

<1:9.0.120-1.el8_8
  • H
Improper Handling of Case Sensitivity

<1:9.0.120-1.el8_8
  • H
Incorrect Implementation of Authentication Algorithm

<1:9.0.120-1.el8_8
  • H
Information Exposure

<1:9.0.120-1.el8_8
  • H
Improper Validation of Syntactic Correctness of Input

<1:9.0.120-1.el8_8
  • H
Insecure Default Initialization of Resource

<1:9.0.120-1.el8_8
  • H
Reliance on Untrusted Inputs in a Security Decision

<1:9.0.120-1.el8_8
  • H
Authentication Bypass by Primary Weakness

<1:9.0.120-1.el8_8
  • H
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

<1:9.0.120-1.el8_8
  • H
Improper Handling of Case Sensitivity

<1:9.0.120-1.el8_8
  • H
Incorrect Implementation of Authentication Algorithm

<1:9.0.120-1.el8_8
  • H
Information Exposure

<1:9.0.120-1.el8_8
  • H
Improper Validation of Syntactic Correctness of Input

<1:9.0.120-1.el8_8
  • H
Reliance on Untrusted Inputs in a Security Decision

<1:9.0.87-2.el8_10
  • H
Use of a Risky Cryptographic Primitive

<1:9.0.87-2.el8_10
  • H
Reliance on Untrusted Inputs in a Security Decision

<1:9.0.87-2.el8_8
  • H
Use of a Risky Cryptographic Primitive

<1:9.0.87-2.el8_8
  • H
Reliance on Untrusted Inputs in a Security Decision

<1:9.0.87-2.el8_8
  • H
Use of a Risky Cryptographic Primitive

<1:9.0.87-2.el8_8
  • H
Directory Traversal

<1:9.0.87-1.el8_10.7
  • H
Improper Neutralization

<1:9.0.87-1.el8_10.7
  • H
Directory Traversal

<1:9.0.87-1.el8_8.8
  • H
Improper Neutralization

<1:9.0.87-1.el8_8.8
  • H
Directory Traversal

<1:9.0.87-1.el8_8.8
  • H
Improper Neutralization

<1:9.0.87-1.el8_8.8
  • H
Resource Exhaustion

<1:9.0.87-1.el8_10.6
  • H
Integer Overflow or Wraparound

<1:9.0.87-1.el8_10.6
  • H
Race Condition

<1:9.0.87-1.el8_10.6
  • H
Authentication Bypass

<1:9.0.87-1.el8_10.6
  • H
Resource Exhaustion

<1:9.0.87-1.el8_10.6
  • H
Allocation of Resources Without Limits or Throttling

<1:9.0.87-1.el8_10.6
  • H
Allocation of Resources Without Limits or Throttling

<1:9.0.87-1.el8_10.6
  • H
Resource Exhaustion

<1:9.0.87-1.el8_8.7
  • H
Integer Overflow or Wraparound

<1:9.0.87-1.el8_8.7
  • H
Race Condition

<1:9.0.87-1.el8_8.7
  • H
Authentication Bypass

<1:9.0.87-1.el8_8.7
  • H
Resource Exhaustion

<1:9.0.87-1.el8_8.7
  • H
Allocation of Resources Without Limits or Throttling

<1:9.0.87-1.el8_8.7
  • H
Allocation of Resources Without Limits or Throttling

<1:9.0.87-1.el8_8.7
  • H
Resource Exhaustion

<1:9.0.87-1.el8_8.7
  • H
Integer Overflow or Wraparound

<1:9.0.87-1.el8_8.7
  • H
Race Condition

<1:9.0.87-1.el8_8.7
  • H
Authentication Bypass

<1:9.0.87-1.el8_8.7
  • H
Resource Exhaustion

<1:9.0.87-1.el8_8.7
  • H
Allocation of Resources Without Limits or Throttling

<1:9.0.87-1.el8_8.7
  • H
Allocation of Resources Without Limits or Throttling

<1:9.0.87-1.el8_8.7
  • H
Improper Input Validation

<1:9.0.87-1.el8_8.5
  • H
Time-of-check Time-of-use (TOCTOU)

<1:9.0.87-1.el8_8.5
  • H
Improper Input Validation

<1:9.0.87-1.el8_8.5
  • H
Time-of-check Time-of-use (TOCTOU)

<1:9.0.87-1.el8_8.5
  • H
Improper Input Validation

<1:9.0.87-1.el8_10.4
  • H
Time-of-check Time-of-use (TOCTOU)

<1:9.0.87-1.el8_10.4
  • M
Path Equivalence

<1:9.0.87-1.el8_10.3
  • M
Time-of-check Time-of-use (TOCTOU)

<1:9.0.87-1.el8_10.3
  • M
Path Equivalence

<1:9.0.87-1.el8_8.4
  • M
Time-of-check Time-of-use (TOCTOU)

<1:9.0.87-1.el8_8.4
  • M
Path Equivalence

<1:9.0.87-1.el8_8.4
  • M
Time-of-check Time-of-use (TOCTOU)

<1:9.0.87-1.el8_8.4
  • M
Path Equivalence

<1:9.0.87-1.el8_8.4
  • M
Time-of-check Time-of-use (TOCTOU)

<1:9.0.87-1.el8_8.4
  • M
Path Equivalence

<1:9.0.87-1.el8_8.4
  • M
Time-of-check Time-of-use (TOCTOU)

<1:9.0.87-1.el8_8.4
  • H
Resource Exhaustion

<1:9.0.87-1.el8_8.3
  • H
Resource Exhaustion

<1:9.0.87-1.el8_8.3
  • H
Resource Exhaustion

<1:9.0.87-1.el8_8.3
  • H
Resource Exhaustion

<1:9.0.87-1.el8_8.3
  • H
Resource Exhaustion

<1:9.0.87-1.el8_10.2
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<1:9.0.87-1.el8_10.2
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<1:9.0.87-1.el8_8.3
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<1:9.0.87-1.el8_8.3
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<1:9.0.87-1.el8_8.3
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<1:9.0.87-1.el8_8.3
  • H
Improper Input Validation

<1:9.0.87-1.el8_8.2
  • H
Incomplete Cleanup

<1:9.0.87-1.el8_8.2
  • H
Improper Input Validation

<1:9.0.87-1.el8_8.2
  • H
Incomplete Cleanup

<1:9.0.87-1.el8_8.2
  • H
Improper Input Validation

<1:9.0.87-1.el8_8.2
  • H
Incomplete Cleanup

<1:9.0.87-1.el8_8.2
  • H
Improper Input Validation

<1:9.0.87-1.el8_8.2
  • H
Incomplete Cleanup

<1:9.0.87-1.el8_8.2
  • H
Improper Input Validation

<1:9.0.87-1.el8_10.1
  • H
Incomplete Cleanup

<1:9.0.87-1.el8_10.1
  • H
HTTP Request Smuggling

<1:9.0.62-27.el8_9.3
  • H
HTTP Request Smuggling

<1:9.0.62-5.el8_8.3
  • H
HTTP Request Smuggling

<1:9.0.62-5.el8_8.3
  • H
HTTP Request Smuggling

<1:9.0.62-5.el8_8.3
  • H
HTTP Request Smuggling

<1:9.0.62-5.el8_8.3
  • M
Improper Input Validation

<1:9.0.62-27.el8_9.2
  • M
Incomplete Cleanup

<1:9.0.62-27.el8_9.2
  • M
Incomplete Cleanup

<1:9.0.62-27.el8_9.2
  • M
Open Redirect

<1:9.0.62-27.el8_9.2
  • M
Off-by-one Error

<1:9.0.62-27.el8_9
  • M
Information Exposure

<1:9.0.62-27.el8_9
  • M
Allocation of Resources Without Limits or Throttling

<1:9.0.62-27.el8_9
  • H
Resource Exhaustion

<1:9.0.62-5.el8_8.2
  • H
Resource Exhaustion

<1:9.0.62-5.el8_8.2
  • H
Resource Exhaustion

<1:9.0.62-5.el8_8.2
  • H
Resource Exhaustion

<1:9.0.62-5.el8_8.2
  • H
Resource Exhaustion

<1:9.0.62-5.el8_8.2