Apache Tomcat是美国Apache基金会开源的一个Web应用服务器。 Apache Tomcat存在服务供应链问题漏洞,该漏洞可能导致未经身份验证的攻击者通过网络访问获取对数据机密性和完整性的高影响。以下版本受到影响:11.0.0-M1至11.0.23版本、10.1.0-M1至10.1.56版本、9.0.13至9.0.119版本、8.5.38至8.5.100版本和7.0.100至7.0.109版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Tomcat | 11.0.0-M1≤ 11.0.23 |
affected |
10.1.0-M1≤ 10.1.56 |
affected | ||
9.0.13≤ 9.0.119 |
affected | ||
8.5.38≤ 8.5.100 |
affected | ||
7.0.100≤ 7.0.109 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Tomcat | 11.0.0-M1 ~ 11.0.23 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-49488 | Apache OpenMeetings: Arbitrary File Read | |
| CVE-2026-62393 | Apache Kylin: Improper authorization in job information retrieval | |
| CVE-2026-62392 | Apache Kylin: OS Command Injection via Async Query API | |
| CVE-2026-62390 | Apache Kylin: SQL Injection Vulnerability in Catalog Cache Refresh API | |
| CVE-2026-58319 | Apache Doris: Improper Authentication in Frontend HTTP API | |
| CVE-2026-59083 | Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass |
No comments yet