Exposición de Apache Tomcat

Web servers
431
score de exposición
14.239
sitios usan
6
en explotación
27
críticos
Análisis Vexday

Apache Tomcat acumula 131 CVEs catalogadas, das quais 5 estão confirmadas em exploração ativa pelo CISA KEV — representando uma taxa 8,5 vezes acima da média geral do catálogo, sinal claro de que vulnerabilidades nessa tecnologia atraem atenção consistente de agentes maliciosos. O tipo de falha mais recorrente é CWE-20 (validação de entrada imprópria), que historicamente viabiliza desde execução remota de código até desvios de controle de acesso. A CVE mais crítica atualmente ativa, CVE-2017-12617, apresenta EPSS de 0,9999 — praticamente a pontuação máxima de probabilidade de exploração —, exigindo atenção prioritária em qualquer ambiente que ainda execute versões vulneráveis. Os 17 novos registros surgidos nos últimos 90 dias, somados às 19 CVEs de severidade crítica, indicam uma superfície de ataque que segue crescendo e que demanda ciclos de patching frequentes e monitoramento contínuo.

CVEs

151 resultados
CVE-2017-5651In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the refactoring of the HTTP connectors introduced a regression in the send file EPSS 7.8%CVE-2016-6817HIGHThe HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header was received that waEPSS 7.2%CVE-2021-41079Apache Tomcat DoS with unexpected TLS packetEPSS 7.2%CVE-2016-6794When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In EPSS 7.2%CVE-2016-8747HIGHAn information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.0.M15 in reverse-proxy configurations. HEPSS 7.1%CVE-2021-30639DoS after non-blocking IO errorEPSS 6.9%CVE-2022-34305XSS in examples web applicationEPSS 6.7%CVE-2024-52316CRITICALApache Tomcat: Authentication bypass when using Jakarta Authentication APIEPSS 6.2%CVE-2017-15706As part of the fix for bug 61201, the documentation for Apache Tomcat 9.0.0.M22 to 9.0.1, 8.5.16 to 8.5.23, 8.0.45 to 8.0.47 and 7.0.79 to 7EPSS 6.1%CVE-2023-41080Apache Tomcat: Open redirect with FORM authenticationEPSS 6.0%CVE-2023-45648MEDIUMApache Tomcat: Trailer header parsing too lenientEPSS 5.8%CVE-2024-34750HIGHApache Tomcat: HTTP/2 excess header handling DoSEPSS 4.6%CVE-2018-8020Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does not properly check OCSP pre-produced responses, which are lisEPSS 4.2%CVE-2026-50229MEDIUMApache Tomcat: XSS in number guess exampleEPSS 4.1%CVE-2018-8019When using an OCSP responder Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 did not correctly handle invalid responses. This alloEPSS 4.1%CVE-2025-31651CRITICALApache Tomcat: Bypass of rules in Rewrite ValveEPSS 4.0%CVE-2025-48989HIGHApache Tomcat: h2 DoS - Made You ResetEPSS 3.7%CVE-2017-15698When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1.2.0 to 1.2.14 and 1.1.23 to 1.1.34 did not coEPSS 3.5%CVE-2025-49125HIGHApache Tomcat: Security constraint bypass for pre/post-resourcesEPSS 3.4%CVE-2025-46701HIGHApache Tomcat: Security constraint bypass for CGI scriptsEPSS 2.9%