Apache Products Multiple Vulnerabilities
Release Date: 14 Jul 2025
RISK: Medium Risk
TYPE: Servers - Web Servers
Multiple vulnerabilities were identified in Apache products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, data manipulation and security restriction bypass on the targeted system.
Impact
- Denial of Service
- Security Restriction Bypass
- Data Manipulation
System / Technologies affected
- Apache HTTP Server versions prior to 2.4.64
- Apache Tomcat versions prior to 9.0.107
- Apache Tomcat versions prior to 10.1.43
- Apache Tomcat versions prior to 11.0.9
Solutions
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
- Apache HTTP Server version 2.4.64
- Apache Tomcat version 9.0.107
- Apache Tomcat version 10.1.43
- Apache Tomcat version 11.0.9
Vulnerability Identifier
- CVE-2023-38709
- CVE-2024-42516
- CVE-2024-43204
- CVE-2024-43394
- CVE-2024-47252
- CVE-2025-23048
- CVE-2025-49630
- CVE-2025-49812
- CVE-2025-52434
- CVE-2025-52520
- CVE-2025-53020
- CVE-2025-53506
沒有留言:
發佈留言