Exposição de Apache Tomcat

Web servers
411
score de exposição
15.767
sites usam
6
em exploração
24
críticos
Análise Vexday

Apache Tomcat acumula 131 CVEs catalogadas, das quais 5 estão confirmadas em exploração ativa pelo CISA KEV — representando uma taxa 8,5 vezes acima da média geral do catálogo, sinal claro de que vulnerabilidades nessa tecnologia atraem atenção consistente de agentes maliciosos. O tipo de falha mais recorrente é CWE-20 (validação de entrada imprópria), que historicamente viabiliza desde execução remota de código até desvios de controle de acesso. A CVE mais crítica atualmente ativa, CVE-2017-12617, apresenta EPSS de 0,9999 — praticamente a pontuação máxima de probabilidade de exploração —, exigindo atenção prioritária em qualquer ambiente que ainda execute versões vulneráveis. Os 17 novos registros surgidos nos últimos 90 dias, somados às 19 CVEs de severidade crítica, indicam uma superfície de ataque que segue crescendo e que demanda ciclos de patching frequentes e monitoramento contínuo.

CVEs

141 resultados
CVE-2025-48988HIGHApache Tomcat: FileUpload large number of parts with headers DoSEPSS 56.3%CVE-2023-28709Apache Tomcat: Fix for CVE-2023-24998 is incompleteEPSS 49.9%CVE-2018-1323The IIS/ISAPI specific code in the Apache Tomcat JK ISAPI Connector 1.2.0 to 1.2.42 that normalised the requested path before matching it toEPSS 47.0%CVE-2023-24998Apache Commons FileUpload, Apache Tomcat: FileUpload DoS with excessive partsEPSS 46.8%CVE-2019-0221The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escapiEPSS 45.6%CVE-2024-50379CRITICALApache Tomcat: RCE due to TOCTOU issue in JSP compilationEPSS 44.3%CVE-2016-6816The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.47 that parsed the HEPSS 39.6%CVE-2020-11996A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could tEPSS 26.7%CVE-2020-17527Apache Tomcat: Request header mix-up between HTTP/2 streamsEPSS 24.6%CVE-2024-24549HIGHApache Tomcat: HTTP/2 header handling DoSEPSS 23.1%CVE-2021-24122Apache Tomcat information disclosureEPSS 22.9%CVE-2018-8014The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.8EPSS 21.7%CVE-2018-8034HIGHThe host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache TomEPSS 21.3%CVE-2018-1336An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a DenEPSS 20.6%CVE-2021-25122Apache Tomcat h2c request mix-upEPSS 18.1%CVE-2018-1304The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4EPSS 17.4%CVE-2017-5647A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5.12, 8.0.0.RC1 to 8.0.42, 7.0.0 to 7.0.7EPSS 16.8%CVE-2017-5664The error page mechanism of the Java Servlet Specification requires that, when an error occurs and an error page is configured for the errorEPSS 16.6%CVE-2016-8745A bug in the error handling of the send file code for the NIO HTTP connector in Apache Tomcat 9.0.0.M1 to 9.0.0.M13, 8.5.0 to 8.5.8, 8.0.0.REPSS 16.0%CVE-2018-1305Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 tEPSS 14.5%