Apache Software Foundation Apache Tomcat是Apache Software Foundation基金会的应用服务器。 Apache Tomcat存在异常处理不当漏洞,该漏洞源于在配置基于FFM的连接器的CRLs时存在错误条件未处理问题。以下版本受到影响:11.0.0-M1至11.0.22版本、10.1.0-M7至10.1.55版本、9.0.83至9.0.118版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Tomcat | 11.0.0-M1≤ 11.0.22 |
affected |
10.1.0-M7≤ 10.1.55 |
affected | ||
9.0.83≤ 9.0.118 |
affected | ||
≤ 9.0.82 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Tomcat | 11.0.0-M1 ~ 11.0.22 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55957 | Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind | |
| CVE-2026-55956 | Apache Tomcat: Security constraints for default servlet ignored method | |
| CVE-2026-55955 | Apache Tomcat: EncryptInterceptor not protected against replay attacks | |
| CVE-2026-55276 | Apache Tomcat: Logged effective web.xml is incomplete | |
| CVE-2026-53404 | Apache Tomcat: Bad ornext processing in RewriteValve | |
| CVE-2026-50229 | Apache Tomcat: XSS in number guess example |
No comments yet