tomcat vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the tomcat package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • H
Resource Exhaustion

<9.0.98-150200.74.1
  • M
CVE-2024-52317

<9.0.98-150200.74.1
  • H
Time-of-check Time-of-use (TOCTOU)

<9.0.98-150200.74.1
  • C
Unchecked Error Condition

<9.0.97-150200.71.1
  • H
Resource Exhaustion

<9.0.91-150200.68.1
  • H
Improper Input Validation

<9.0.87-150200.65.1
  • H
Incomplete Cleanup

<9.0.87-150200.65.1
  • H
Incorrect Permission Assignment for Critical Resource

<9.0.85-150200.57.1
  • M
HTTP Request Smuggling

<9.0.85-150200.57.1
  • H
Improper Input Validation

<9.0.85-150200.57.1
  • H
Incomplete Cleanup

<9.0.85-150200.57.1
  • M
Incomplete Cleanup

<9.0.85-150200.57.1
  • H
CVE-2023-44487

<9.0.82-150200.46.1
  • M
Open Redirect

<9.0.82-150200.46.1
  • H
Off-by-one Error

<9.0.75-150200.41.1
  • H
Allocation of Resources Without Limits or Throttling

<9.0.75-150200.41.1
  • H
Improper Encoding or Escaping of Output

<9.0.43-150200.38.1
  • H
Unprotected Transport of Credentials

<9.0.43-150200.35.1
  • H
Allocation of Resources Without Limits or Throttling

<9.0.43-150200.35.1