target entity

Apache

39 source-linked records in the current knowledge graph.

high

CVE-2026-34197: Apache ActiveMQ Improper Input Validation Vulnerability

Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-34197EPSS 96.7%ActiveMQApache
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38475: Apache HTTP Server Improper Escaping of Output Vulnerability

Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite that allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-38475EPSS 100.0%ApacheHTTP Server
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24813: Apache Tomcat Path Equivalence Vulnerability

Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24813EPSS 99.9%ApacheTomcat
CISA KEV ↗ · unattributed attribution
high

CVE-2024-45195: Apache OFBiz Forced Browsing Vulnerability

Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-45195EPSS 100.0%ApacheOFBiz
CISA KEV ↗ · unattributed attribution
high

CVE-2024-27348: Apache HugeGraph-Server Improper Access Control Vulnerability

Apache HugeGraph-Server contains an improper access control vulnerability that could allow a remote attacker to execute arbitrary code. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-27348EPSS 99.2%ApacheHugeGraph-Server
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38856: Apache OFBiz Incorrect Authorization Vulnerability

Apache OFBiz contains an incorrect authorization vulnerability that could allow remote code execution via a Groovy payload in the context of the OFBiz user process by an unauthenticated attacker. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38856EPSS 99.4%ApacheOFBiz
CISA KEV ↗ · unattributed attribution
high

CVE-2024-32113: Apache OFBiz Path Traversal Vulnerability

Apache OFBiz contains a path traversal vulnerability that could allow for remote code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-32113EPSS 99.4%ApacheOFBiz
CISA KEV ↗ · unattributed attribution
high

CVE-2020-17519: Apache Flink Improper Access Control Vulnerability

Apache Flink contains an improper access control vulnerability that allows an attacker to read any file on the local filesystem of the JobManager through its REST interface. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2020-17519EPSS 97.9%ApacheFlink
CISA KEV ↗ · unattributed attribution
high

CVE-2023-27524: Apache Superset Insecure Default Initialization of Resource Vulnerability

Apache Superset contains an insecure default initialization of a resource vulnerability that allows an attacker to authenticate and access unauthorized resources on installations that have not altered the default configured SECRET_KEY according to installation instructions. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-27524EPSS 97.4%ApacheSuperset
CISA KEV ↗ · unattributed attribution
high

CVE-2023-46604: Apache ActiveMQ Deserialization of Untrusted Data Vulnerability

Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-46604EPSS 99.7%ActiveMQApache
CISA KEV ↗ · unattributed attribution
high

CVE-2023-33246: Apache RocketMQ Command Execution Vulnerability

Several components of Apache RocketMQ, including NameServer, Broker, and Controller, are exposed to the extranet and lack permission verification. An attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as or achieve the same effect by forging the RocketMQ protocol content. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-33246EPSS 96.6%ApacheRocketMQ
CISA KEV ↗ · unattributed attribution
high

CVE-2016-8735: Apache Tomcat Remote Code Execution Vulnerability

Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn't updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types. Required action: Apply updates per vendor instructions.

CVE-2016-3427CVE-2016-8735EPSS 92.3%ApacheTomcat
CISA KEV ↗ · unattributed attribution
high

CVE-2021-45046: Apache Log4j2 Deserialization of Untrusted Data Vulnerability

Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations. Required action: Apply updates per vendor instructions.

CVE-2021-44228CVE-2021-45046EPSS 100.0%ApacheLog4j2
CISA KEV ↗ · unattributed attribution
high

CVE-2017-12617: Apache Tomcat Remote Code Execution Vulnerability

When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server. Required action: Apply updates per vendor instructions.

CVE-2017-12617EPSS 100.0%ApacheTomcat
CISA KEV ↗ · unattributed attribution
high

CVE-2017-12615: Apache Tomcat on Windows Remote Code Execution Vulnerability

When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server. Required action: Apply updates per vendor instructions.

CVE-2017-12615EPSS 99.6%ApacheTomcat
CISA KEV ↗ · unattributed attribution
high

CVE-2020-1938: Apache Tomcat Improper Privilege Management Vulnerability

Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited. Required action: Apply updates per vendor instructions.

CVE-2020-1938EPSS 99.3%ApacheTomcat
CISA KEV ↗ · unattributed attribution
high

CVE-2020-11978: Apache Airflow Command Injection

A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow. Required action: Apply updates per vendor instructions.

CVE-2020-11978EPSS 99.1%AirflowApache
CISA KEV ↗ · unattributed attribution
high

CVE-2021-44228: Apache Log4j2 Remote Code Execution Vulnerability

Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution. Required action: For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.

CVE-2021-44228EPSS 100.0%ApacheLog4j2
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2021-40438: Apache HTTP Server-Side Request Forgery (SSRF)

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. Required action: Apply updates per vendor instructions.

CVE-2021-40438EPSS 100.0%Apache
CISA KEV ↗ · unattributed attribution
high

CVE-2021-42013: Apache HTTP Server Path Traversal Vulnerability

Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773. Required action: Apply updates per vendor instructions.

CVE-2021-41773CVE-2021-42013EPSS 100.0%ApacheHTTP Server
CISA KEV ↗ · unattributed attribution
high

CVE-2021-41773: Apache HTTP Server Path Traversal Vulnerability

Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all denied� or if CGI scripts are enabled. The original patch issued under this CVE ID is insufficient, please review remediation information under CVE-2021-42013. Required action: Apply updates per vendor instructions.

CVE-2021-41773CVE-2021-42013EPSS 100.0%ApacheHTTP Server
CISA KEV ↗ · unattributed attribution
high

CVE-2019-0211: Apache HTTP Server Privilege Escalation Vulnerability

Apache HTTP Server, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute code with the privileges of the parent process (usually root) by manipulating the scoreboard. Required action: Apply updates per vendor instructions.

CVE-2019-0211EPSS 65.0%ApacheHTTP Server
CISA KEV ↗ · unattributed attribution
high

CVE-2016-4437: Apache Shiro Code Execution Vulnerability

Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the "remember me" feature. Required action: Apply updates per vendor instructions.

CVE-2016-4437EPSS 93.0%ApacheShiro
CISA KEV ↗ · unattributed attribution
high

CVE-2018-11776: Apache Struts Remote Code Execution Vulnerability

Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defined in underlying configurations and in same time, its upper package configuration have no or wildcard namespace. Or, using URL tag which doesn't have value and action set and in same time, its upper package configuration have no or wildcard namespace. Required action: Apply updates per vendor instructions.

CVE-2018-11776EPSS 100.0%ApacheStruts
CISA KEV ↗ · unattributed attribution