2025年10月31日星期五

Apache Products Multiple Vulnerabilities

Apache Products Multiple Vulnerabilities

Release Date: 30 Oct 2025

RISK: Medium Risk

TYPE: Servers - Web Servers

Multiple vulnerabilities were identified in Apache products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, spoofing and security restriction bypass on the targeted system.


Impact

  • Denial of Service
  • Security Restriction Bypass
  • Spoofing

System / Technologies affected

  • Apache Tomcat versions from 9.0.0.M1 to 9.0.109
  • Apache Tomcat versions from 10.1.0-M1 to 10.1.46
  • Apache Tomcat versions from 11.0.0-M1 to 11.0.11

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

  • Update to Apache Tomcat version 9.0.110 or later
  • Update to Apache Tomcat version 10.1.47 or later
  • Update to Apache Tomcat version 11.0.12 or later

Vulnerability Identifier


Source


Related Link

沒有留言:

發佈留言

Jenkins 多個漏洞

Jenkins 多個漏洞 發佈日期: 2026年03月20日 風險: 中度風險 類型: 伺服器 - 互聯網應用伺服器 於 Jenkins 發現多...