Apache Tomcat Multiple Vulnerabilities
Release Date: 18 Jun 2025
RISK: Medium Risk
TYPE: Servers - Web Servers
Multiple vulnerabilities were identified in Apache Tomcat. A remote attacker could exploit some of these vulnerabilities to trigger security restriction bypass and denial of service condition on the targeted system.
Impact
- Denial of Service
- Security Restriction Bypass
System / Technologies affected
- Apache Tomcat version 9.0.0.M1 to 9.0.105
- Apache Tomcat version 10.1.0-M1 to 10.1.41
- Apache Tomcat version 11.0.0-M1 to 11.0.7
Solutions
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
- https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.106
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.42
- https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.8
沒有留言:
發佈留言