target entity

Tomcat

5 source-linked records in the current knowledge graph.

high

CVE-2025-24813: Apache Tomcat Path Equivalence Vulnerability

Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24813EPSS 99.9%ApacheTomcat
CISA KEV ↗ · unattributed attribution
high

CVE-2016-8735: Apache Tomcat Remote Code Execution Vulnerability

Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn't updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types. Required action: Apply updates per vendor instructions.

CVE-2016-3427CVE-2016-8735EPSS 92.3%ApacheTomcat
CISA KEV ↗ · unattributed attribution
high

CVE-2017-12617: Apache Tomcat Remote Code Execution Vulnerability

When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server. Required action: Apply updates per vendor instructions.

CVE-2017-12617EPSS 100.0%ApacheTomcat
CISA KEV ↗ · unattributed attribution
high

CVE-2017-12615: Apache Tomcat on Windows Remote Code Execution Vulnerability

When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server. Required action: Apply updates per vendor instructions.

CVE-2017-12615EPSS 99.6%ApacheTomcat
CISA KEV ↗ · unattributed attribution
high

CVE-2020-1938: Apache Tomcat Improper Privilege Management Vulnerability

Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited. Required action: Apply updates per vendor instructions.

CVE-2020-1938EPSS 99.3%ApacheTomcat
CISA KEV ↗ · unattributed attribution