Apache Tomcat Multiple Vulnerabilities
Release Date: 30 Apr 2025
RISK: Medium Risk
TYPE: Servers - Web Servers
Multiple vulnerabilities were identified in Apache Tomcat. A remote attacker could exploit some of these vulnerabilities to trigger security restriction bypass and denial of service condition on the targeted system.
Impact
- Denial of Service
- Security Restriction Bypass
System / Technologies affected
- Apache Tomcat version 11.0.0-M2 to 11.0.5
- Apache Tomcat version 10.1.10 to 10.1.39
- Apache Tomcat version 9.0.76 to 9.0.102
Solutions
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
- https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.104
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.40
- https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.6
沒有留言:
發佈留言