Known vulnerabilities in Apache Foundation Apache Tomcat 9.0.60

Website: https://www.apache.org
Total Security Bulletins: 27

Security bulletins (27)

Secuity bulletin Severity Status Published
SB2025102749: Remote denial of service in Apache Tomcat Medium
Patched
27.10.2025
SB2025102748: Two vulnerabilities in Apache Tomcat High
Patched Public exploit
27.10.2025
SB2025082650: Session Fixation in Apache Tomcat Medium
Patched
26.08.2025
SB2025081375: Remote denial of service in Apache Tomcat Medium
Patched
13.08.2025
SB20250704167: Multiple vulnerabilities in Apache Tomcat Medium
Patched
04.07.2025
SB2025061634: Multiple vulnerabilities in Apache Tomcat Medium
Patched Public exploit
16.06.2025
SB2025053002: Security restrictions bypass in Apache Tomcat Low
Patched Public exploit
30.05.2025
SB2025042851: Multiple vulnerabilities in Apache Tomcat Medium
Patched Public exploit
28.04.2025
SB2025031069: Improper validation of files in Apache Tomcat Critical
Patched Exploited
10.03.2025
SB2024122063: Remote code execution in Apache Tomcat High
Patched
20.12.2024
SB2024121745: Multiple vulnerabilities in Apache Tomcat Medium
Patched Public exploit
17.12.2024
SB2024111830: Cross-site scripting in Apache Tomcat Medium
Patched
18.11.2024
SB2024111823: Multiple vulnerabilities in Apache Tomcat Medium
Patched Public exploit
18.11.2024
SB2024092355: Denial of service in Apache Tomcat Medium
Patched
23.09.2024
SB2024070346: Denial of service in Apache Tomcat Medium
Patched
03.07.2024
SB2024031386: Multiple vulnerabilities in Apache Tomcat Medium
Patched Public exploit
13.03.2024
SB2023112846: HTTP request smuggling in Apache Tomcat Medium
Patched
28.11.2023
SB2023101084: Multiple vulnerabilities in Apache Tomcat Medium
Patched Exploited
10.10.2023
SB2023082924: Open redirect in Apache Tomcat Medium
Patched Public exploit
29.08.2023
SB2023052235: Denial of service in Apache Tomcat Medium
Patched
22.05.2023
SB2023032237: Insecure cookie configuration in Apache Tomcat Low
Patched
22.03.2023
SB2023022047: Denial of service in Apache Tomcat FileUpload component Medium
Patched
20.02.2023
SB2023010329: Code injection in Apache Tomcat Medium
Patched
03.01.2023
SB2022103146: HTTP request smuggling in Apache Tomcat Medium
Patched
31.10.2022
SB2022092818: Information disclosure in Apache Tomcat Low
Patched
28.09.2022
SB2022062338: XSS in Apache Tomcat Medium
Patched Public exploit
23.06.2022
SB2022051612: Denial of service in Apache Tomcat Low
Patched Public exploit
16.05.2022