Direct Vulnerabilities

Known vulnerabilities in the tomcat package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Reliance on Untrusted Inputs in a Security Decision

*
  • L
Inappropriate Encoding for Output Context

*
  • M
Incomplete Blacklist

*
  • M
Incorrect Implementation of Authentication Algorithm

*
  • L
HTTP Request Smuggling

*
  • L
File and Directory Information Exposure

*
  • L
External Control of System or Configuration Setting

*
  • H
Use of a Risky Cryptographic Primitive

*
  • M
Incorrect Implementation of Authentication Algorithm

*
  • L
Open Redirect

*
  • M
Improper Validation of Unsafe Equivalence in Input

*
  • H
Improper Certificate Validation

*
  • L
Improper Input Validation

*
  • H
Directory Traversal

<1:9.0.87-1.el8_10.7
  • H
Improper Neutralization

<1:9.0.87-1.el8_10.7
  • H
Directory Traversal

<1:9.0.87-1.el8_8.8
  • H
Improper Neutralization

<1:9.0.87-1.el8_8.8
  • H
Directory Traversal

<1:9.0.87-1.el8_8.8
  • H
Improper Neutralization

<1:9.0.87-1.el8_8.8
  • H
Resource Exhaustion

<1:9.0.87-1.el8_10.6
  • H
Integer Overflow or Wraparound

<1:9.0.87-1.el8_10.6
  • H
Race Condition

<1:9.0.87-1.el8_10.6
  • H
Authentication Bypass

<1:9.0.87-1.el8_10.6
  • H
Resource Exhaustion

<1:9.0.87-1.el8_10.6
  • H
Allocation of Resources Without Limits or Throttling

<1:9.0.87-1.el8_10.6
  • H
Allocation of Resources Without Limits or Throttling

<1:9.0.87-1.el8_10.6
  • H
Resource Exhaustion

<1:9.0.87-1.el8_8.7
  • H
Integer Overflow or Wraparound

<1:9.0.87-1.el8_8.7
  • H
Race Condition

<1:9.0.87-1.el8_8.7
  • H
Authentication Bypass

<1:9.0.87-1.el8_8.7
  • H
Resource Exhaustion

<1:9.0.87-1.el8_8.7
  • H
Allocation of Resources Without Limits or Throttling

<1:9.0.87-1.el8_8.7
  • H
Allocation of Resources Without Limits or Throttling

<1:9.0.87-1.el8_8.7
  • H
Resource Exhaustion

<1:9.0.87-1.el8_8.7
  • H
Integer Overflow or Wraparound

<1:9.0.87-1.el8_8.7
  • H
Race Condition

<1:9.0.87-1.el8_8.7
  • H
Authentication Bypass

<1:9.0.87-1.el8_8.7
  • H
Resource Exhaustion

<1:9.0.87-1.el8_8.7
  • H
Allocation of Resources Without Limits or Throttling

<1:9.0.87-1.el8_8.7
  • H
Allocation of Resources Without Limits or Throttling

<1:9.0.87-1.el8_8.7
  • H
Improper Input Validation

<1:9.0.87-1.el8_8.5
  • H
Time-of-check Time-of-use (TOCTOU)

<1:9.0.87-1.el8_8.5
  • H
Improper Input Validation

<1:9.0.87-1.el8_8.5
  • H
Time-of-check Time-of-use (TOCTOU)

<1:9.0.87-1.el8_8.5
  • H
Improper Input Validation

<1:9.0.87-1.el8_10.4
  • H
Time-of-check Time-of-use (TOCTOU)

<1:9.0.87-1.el8_10.4
  • M
Improper Handling of Case Sensitivity

*
  • L
Improper Neutralization

*
  • M
Path Equivalence

<1:9.0.87-1.el8_10.3
  • M
Time-of-check Time-of-use (TOCTOU)

<1:9.0.87-1.el8_10.3
  • M
Path Equivalence

<1:9.0.87-1.el8_8.4
  • M
Time-of-check Time-of-use (TOCTOU)

<1:9.0.87-1.el8_8.4
  • M
Path Equivalence

<1:9.0.87-1.el8_8.4
  • M
Time-of-check Time-of-use (TOCTOU)

<1:9.0.87-1.el8_8.4
  • M
Path Equivalence

<1:9.0.87-1.el8_8.4
  • M
Time-of-check Time-of-use (TOCTOU)

<1:9.0.87-1.el8_8.4
  • M
Path Equivalence

<1:9.0.87-1.el8_8.4
  • M
Time-of-check Time-of-use (TOCTOU)

<1:9.0.87-1.el8_8.4
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • H
Resource Exhaustion

<1:9.0.87-1.el8_8.3
  • H
Resource Exhaustion

<1:9.0.87-1.el8_8.3
  • H
Resource Exhaustion

<1:9.0.87-1.el8_8.3
  • H
Resource Exhaustion

<1:9.0.87-1.el8_8.3
  • H
Resource Exhaustion

<1:9.0.87-1.el8_10.2
  • H
Resource Exhaustion

*
  • H
Resource Exhaustion

<1:9.0.87-1.el8_10.2
  • H
Resource Exhaustion

<1:9.0.87-1.el8_8.3
  • H
Resource Exhaustion

<1:9.0.87-1.el8_8.3
  • H
Resource Exhaustion

<1:9.0.87-1.el8_8.3
  • H
Resource Exhaustion

<1:9.0.87-1.el8_8.3
  • H
Improper Input Validation

<1:9.0.87-1.el8_8.2
  • H
Incomplete Cleanup

<1:9.0.87-1.el8_8.2
  • H
Improper Input Validation

<1:9.0.87-1.el8_8.2
  • H
Incomplete Cleanup

<1:9.0.87-1.el8_8.2
  • H
Improper Input Validation

<1:9.0.87-1.el8_8.2
  • H
Incomplete Cleanup

<1:9.0.87-1.el8_8.2
  • H
Improper Input Validation

<1:9.0.87-1.el8_8.2
  • H
Incomplete Cleanup

<1:9.0.87-1.el8_8.2
  • H
Improper Input Validation

<1:9.0.87-1.el8_10.1
  • H
Incomplete Cleanup

<1:9.0.87-1.el8_10.1
  • H
HTTP Request Smuggling

<1:9.0.62-27.el8_9.3
  • H
HTTP Request Smuggling

<1:9.0.62-5.el8_8.3
  • H
HTTP Request Smuggling

<1:9.0.62-5.el8_8.3
  • H
HTTP Request Smuggling

<1:9.0.62-5.el8_8.3
  • H
HTTP Request Smuggling

<1:9.0.62-5.el8_8.3
  • M
Improper Input Validation

<1:9.0.62-27.el8_9.2
  • M
Incomplete Cleanup

<1:9.0.62-27.el8_9.2
  • M
Incomplete Cleanup

<1:9.0.62-27.el8_9.2
  • M
Open Redirect

<1:9.0.62-27.el8_9.2
  • M
Off-by-one Error

<1:9.0.62-27.el8_9
  • M
Information Exposure

<1:9.0.62-27.el8_9
  • M
Allocation of Resources Without Limits or Throttling

<1:9.0.62-27.el8_9
  • H
Resource Exhaustion

<1:9.0.62-5.el8_8.2
  • H
Resource Exhaustion

<1:9.0.62-5.el8_8.2
  • H
Resource Exhaustion

<1:9.0.62-5.el8_8.2
  • H
Resource Exhaustion

<1:9.0.62-5.el8_8.2
  • H
Resource Exhaustion

<1:9.0.62-5.el8_8.2
  • M
Open Redirect

*