Security News

Cybersecurity news aggregator

🔓
HIGH Vulnerabilities HKCERT

Apache Tomcat Multiple Vulnerabilities

Multiple vulnerabilities in Apache Tomcat, including cross-site scripting, privilege escalation, and security restriction bypass, could be exploited by a remote attacker. Affected versions are Tomcat 9.0.0.M1 to 9.0.118, 10.1.0-M1 to 10.1.55, and 11.0.0-M1 to 11.0.22. Patches are available in Tomcat versions 9.0.119, 10.1.56, and 11.0.23, which should be applied via the official vendor links.
Read Full Article →

Multiple vulnerabilities were identified in Apache Tomcat. A remote attacker could exploit some of these vulnerabilities to trigger cross-site scripting, elevation of privilege and security restriction bypass on the targeted system. Impact Elevation of Privilege Security Restriction Bypass Cross-Site Scripting System / Technologies affected Apache Tomcat version 9.0.0.M1 to 9.0.118 Apache Tomcat version 10.1.0-M1 to 10.1.55 Apache Tomcat version 11.0.0-M1 to 11.0.22 Solutions Before installation of the software, please visit the vendor web-site for more details. Apply fixes issued by the vendor: https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.119 https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.56 https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.23

Share this article