Apache Tomcat是美国阿帕奇(Apache)基金会的一款轻量级Web应用服务器。该程序实现了对Servlet和JavaServer Page(JSP)的支持。 Apache Tomcat 存在输入验证错误漏洞,该漏洞源于程序处理某些 TLS 数据包时存在无限循环,远程攻击者可以向应用程序发送特制的数据包,消耗所有可用的系统资源并导致拒绝服务条件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Tomcat | Apache Tomcat 8.5 8.5.0 to 8.5.63 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-40438 | mod_proxy SSRF | |
| CVE-2021-39275 | ap_escape_quotes buffer overflow | |
| CVE-2021-39239 | XML External Entity (XXE) vulnerability | |
| CVE-2021-36160 | mod_proxy_uwsgi out of bound read | |
| CVE-2021-34798 | NULL pointer dereference in httpd core |
No comments yet