tomcat-webapps

Direct Vulnerabilities

Known vulnerabilities in the tomcat-webapps package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Improper Access Control

<9.0.121-160000.1.1
  • M
Improper Authentication

<9.0.121-160000.1.1
  • M
Insufficient Session Expiration

<9.0.121-160000.1.1
  • M
Improper Authorization

<9.0.121-160000.1.1
  • M
Incorrect Authorization

<9.0.121-160000.1.1
  • H
Off-by-one Error

<9.0.121-160000.1.1
  • M
Authentication Bypass

<9.0.121-160000.1.1
  • H
Resource Exhaustion

<9.0.121-160000.1.1
  • H
Resource Exhaustion

<9.0.121-160000.1.1
  • H
Improper Input Validation

<9.0.121-160000.1.1
  • H
Improper Input Validation

<9.0.121-160000.1.1
  • M
Time-of-check Time-of-use (TOCTOU)

<9.0.121-160000.1.1
  • H
Resource Exhaustion

<9.0.121-160000.1.1
  • H
Off-by-one Error

<9.0.121-160000.1.1
  • M
Insufficient Session Expiration

<9.0.121-160000.1.1
  • M
Incorrect Authorization

<9.0.121-160000.1.1
  • H
Resource Exhaustion

<9.0.121-160000.1.1
  • H
Improper Input Validation

<9.0.121-160000.1.1
  • M
Improper Authentication

<9.0.121-160000.1.1
  • M
Time-of-check Time-of-use (TOCTOU)

<9.0.121-160000.1.1
  • M
Improper Authorization

<9.0.121-160000.1.1
  • M
Authentication Bypass

<9.0.121-160000.1.1
  • H
Improper Input Validation

<9.0.121-160000.1.1
  • H
Improper Access Control

<9.0.121-160000.1.1
  • M
Detection of Error Condition Without Action

<9.0.119-160000.1.1
  • M
Improper Authorization

<9.0.119-160000.1.1
  • M
Cross-site Scripting (XSS)

<9.0.119-160000.1.1
  • M
Improper Authentication

<9.0.119-160000.1.1
  • L
Always-Incorrect Control Flow Implementation

<9.0.119-160000.1.1
  • M
Always-Incorrect Control Flow Implementation

<9.0.119-160000.1.1
  • M
Improper Handling of Case Sensitivity

<9.0.118-160000.1.1
  • H
Improper Authorization

<9.0.118-160000.1.1
  • H
Authentication Bypass

<9.0.118-160000.1.1
  • M
Information Exposure

<9.0.118-160000.1.1
  • M
Information Exposure

<9.0.118-160000.1.1
  • M
Allocation of Resources Without Limits or Throttling

<9.0.118-160000.1.1
  • H
Improper Input Validation

<9.0.118-160000.1.1
  • M
CVE-2026-34500

<9.0.117-160000.1.1
  • M
Improper Encoding or Escaping of Output

<9.0.117-160000.1.1
  • M
Information Exposure Through Log Files

<9.0.117-160000.1.1
  • M
CVE-2026-29129

<9.0.117-160000.1.1
  • M
Open Redirect

<9.0.117-160000.1.1
  • H
Improper Input Validation

<9.0.117-160000.1.1
  • H
Improper Certificate Validation

<9.0.117-160000.1.1
  • M
CVE-2026-29145

<9.0.117-160000.1.1
  • H
Missing Encryption of Sensitive Data

<9.0.117-160000.1.1
  • H
CVE-2026-29146

<9.0.117-160000.1.1
  • M
HTTP Request Smuggling

<9.0.117-160000.1.1
  • H
Directory Traversal

<9.0.111-160000.1.1
  • M
Improper Resource Shutdown or Release

<9.0.111-160000.1.1
  • M
Improper Neutralization

<9.0.111-160000.1.1