Apache Software Foundation Apache Tomcat是Apache Software Foundation基金会的应用服务器。 Apache Tomcat存在授权问题漏洞,该漏洞源于在配置JNDIRealm使用GSSAPI进行身份验证时缺少关键步骤,允许攻击者在未提供正确密码的情况下进行身份验证。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Tomcat | 11.0.0-M1≤ 11.0.4 |
affected |
10.1.0-M1≤ 10.1.36 |
affected | ||
9.0.0.M1≤ 9.0.100 |
affected | ||
8.5.0≤ 8.5.100 |
affected | ||
7.0.0≤ 7.0.109 |
affected | ||
< 7.0.0 |
unknown |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Tomcat | 11.0.0-M1 ~ 11.0.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55956 | Apache Tomcat: Security constraints for default servlet ignored method | |
| CVE-2026-55955 | Apache Tomcat: EncryptInterceptor not protected against replay attacks | |
| CVE-2026-55276 | Apache Tomcat: Logged effective web.xml is incomplete | |
| CVE-2026-53434 | Apache Tomcat: Invalid CRL configuration doesn't trigger failure for FFM Connector | |
| CVE-2026-53404 | Apache Tomcat: Bad ornext processing in RewriteValve | |
| CVE-2026-50229 | Apache Tomcat: XSS in number guess example |
No comments yet