tomcat9 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the tomcat9 package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • H
Deserialization of Untrusted Data

<9.0.16-3ubuntu0.18.04.2+esm6
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • H
CVE-2023-44487

<9.0.16-3ubuntu0.18.04.2+esm5
  • L
CVE-2021-25329

<9.0.16-3ubuntu0.18.04.2
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Improper Input Validation

<9.0.16-3ubuntu0.18.04.2
  • M
Improper Authentication

<9.0.16-3ubuntu0.18.04.2
  • M
HTTP Request Smuggling

<9.0.16-3ubuntu0.18.04.2
  • M
Information Exposure

<9.0.16-3ubuntu0.18.04.2
  • M
Information Exposure

<9.0.16-3ubuntu0.18.04.2
  • L
Deserialization of Untrusted Data

<9.0.16-3ubuntu0.18.04.2
  • L
Improper Input Validation

*
  • M
Improper Locking

<9.0.16-3ubuntu0.18.04.1
  • L
Cross-site Scripting (XSS)

<9.0.16-3ubuntu0.18.04.1
  • L
Directory Traversal

<9.0.16-3~18.04.1