Exposure of Apache Tomcat

Web servers
431
exposure score
14,239
sites use
6
exploited
27
critical
Vexday analysis

Apache Tomcat acumula 131 CVEs catalogadas, das quais 5 estão confirmadas em exploração ativa pelo CISA KEV — representando uma taxa 8,5 vezes acima da média geral do catálogo, sinal claro de que vulnerabilidades nessa tecnologia atraem atenção consistente de agentes maliciosos. O tipo de falha mais recorrente é CWE-20 (validação de entrada imprópria), que historicamente viabiliza desde execução remota de código até desvios de controle de acesso. A CVE mais crítica atualmente ativa, CVE-2017-12617, apresenta EPSS de 0,9999 — praticamente a pontuação máxima de probabilidade de exploração —, exigindo atenção prioritária em qualquer ambiente que ainda execute versões vulneráveis. Os 17 novos registros surgidos nos últimos 90 dias, somados às 19 CVEs de severidade crítica, indicam uma superfície de ataque que segue crescendo e que demanda ciclos de patching frequentes e monitoramento contínuo.

CVEs

151 results
CVE-2020-13943If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum nuEPSS 57.3%CVE-2020-9484When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is ableEPSS 56.6%CVE-2023-24998Apache Commons FileUpload, Apache Tomcat: FileUpload DoS with excessive partsEPSS 48.8%CVE-2023-28709Apache Tomcat: Fix for CVE-2023-24998 is incompleteEPSS 48.0%CVE-2016-6816The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.47 that parsed the HEPSS 47.4%CVE-2024-50379CRITICALApache Tomcat: RCE due to TOCTOU issue in JSP compilationEPSS 44.3%CVE-2025-48988HIGHApache Tomcat: FileUpload large number of parts with headers DoSEPSS 30.5%CVE-2020-11996A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could tEPSS 26.7%CVE-2020-17527Apache Tomcat: Request header mix-up between HTTP/2 streamsEPSS 24.6%CVE-2024-24549HIGHApache Tomcat: HTTP/2 header handling DoSEPSS 23.1%CVE-2021-24122Apache Tomcat information disclosureEPSS 22.9%CVE-2018-8034HIGHThe host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache TomEPSS 20.9%CVE-2018-1336An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a DenEPSS 20.6%CVE-2018-8014The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.8EPSS 19.4%CVE-2021-25122Apache Tomcat h2c request mix-upEPSS 18.1%CVE-2017-5664The error page mechanism of the Java Servlet Specification requires that, when an error occurs and an error page is configured for the errorEPSS 16.6%CVE-2017-5647A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5.12, 8.0.0.RC1 to 8.0.42, 7.0.0 to 7.0.7EPSS 16.3%CVE-2018-1304The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4EPSS 15.3%CVE-2016-8745A bug in the error handling of the send file code for the NIO HTTP connector in Apache Tomcat 9.0.0.M1 to 9.0.0.M13, 8.5.0 to 8.5.8, 8.0.0.REPSS 14.9%CVE-2018-1305Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 tEPSS 14.3%