Exposición de Apache Tomcat

Web servers
431
score de exposición
14.239
sitios usan
6
en explotación
27
críticos
Análisis Vexday

Apache Tomcat acumula 131 CVEs catalogadas, das quais 5 estão confirmadas em exploração ativa pelo CISA KEV — representando uma taxa 8,5 vezes acima da média geral do catálogo, sinal claro de que vulnerabilidades nessa tecnologia atraem atenção consistente de agentes maliciosos. O tipo de falha mais recorrente é CWE-20 (validação de entrada imprópria), que historicamente viabiliza desde execução remota de código até desvios de controle de acesso. A CVE mais crítica atualmente ativa, CVE-2017-12617, apresenta EPSS de 0,9999 — praticamente a pontuação máxima de probabilidade de exploração —, exigindo atenção prioritária em qualquer ambiente que ainda execute versões vulneráveis. Os 17 novos registros surgidos nos últimos 90 dias, somados às 19 CVEs de severidade crítica, indicam uma superfície de ataque que segue crescendo e que demanda ciclos de patching frequentes e monitoramento contínuo.

CVEs

151 resultados
CVE-2024-21733MEDIUMApache Tomcat: Leaking of unrelated request bodies in default error pageEPSS 14.3%CVE-2017-5648While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.EPSS 13.5%CVE-2021-42340DoS via memory leak with WebSocket connectionsEPSS 11.8%CVE-2018-8037If an async request was completed by the application at the same time as the container triggered the async timeout, a race condition existedEPSS 10.7%CVE-2019-17563When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where anEPSS 10.7%CVE-2016-5018In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application EPSS 10.3%CVE-2025-55754CRITICALApache Tomcat: console manipulation via escape sequences in log messagesEPSS 10.1%CVE-2021-30640Auth weakness in JNDIRealmEPSS 9.9%CVE-2021-25329Incomplete fix for CVE-2020-9484EPSS 9.5%CVE-2020-1935In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsinEPSS 9.4%CVE-2024-56337CRITICALApache Tomcat: RCE due to TOCTOU issue in JSP compilation - CVE-2024-50379 mitigation was incompleteEPSS 9.0%CVE-2019-17569The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the EPSS 8.9%CVE-2026-29146HIGHApache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by defaultEPSS 8.8%CVE-2017-7675The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M21 and 8.5.0 to 8.5.15 bypassed a number of security checks that prevented dirEPSS 8.8%CVE-2022-25762Response mix-up with WebSocket concurrent send and closeEPSS 8.4%CVE-2016-6796A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 toEPSS 8.3%CVE-2016-6797The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0EPSS 8.1%CVE-2016-0762The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to EPSS 8.0%CVE-2017-5650In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the handling of an HTTP/2 GOAWAY frame for a connection did not close streams asEPSS 7.8%CVE-2017-5651In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the refactoring of the HTTP connectors introduced a regression in the send file EPSS 7.5%