Skip to main content
Hit enter to search or ESC to close
Close Search
Menu
Binary Subscriptions
TomEE for Oracle Insurance Policy Administration Suite
TomEE for OpenText Web Experience Management
TomEE for OpenText Process Suite Platform
TomEE for OpenText AppWorks Platform
TomEE for Dassault Systemes SIMULIA Isight
TomEE for Dassault Systemes 3DEXPERIENCE Platform
Tomcat for Dassault Systemes ENOVIA
Tomcat for Progress OpenEdge
Support Subscriptions
Apache TomEE Support
Apache ActiveMQ Support
Apache Tomcat Support
CVE Patching
Enterprise Support
Tomitribe Community Partnership Program
CVE Index
Resources
Blog
Case Studies & Reports
Tribe’s Videos
Company
About Tomitribe
Community
Contact Us
Login
Get A Quote
Apache Tomcat 10.0.x Support
Common Vulnerabilities & Exposures (CVE)
First release:
2021-02-02
Support Lifecycle:
Full Support
CVEs:
22
Namespace:
jakarta
Get Support
What Versions do we cover?
10.0.0
10.0.2
10.0.4
10.0.5
10.0.6
10.0.7
10.0.8
10.0.10
10.0.11
10.0.12
10.0.13
10.0.14
10.0.16
10.0.17
10.0.18
10.0.20
10.0.21
10.0.22
10.0.23
10.0.26
10.0.27
Latest Apache Tomcat 10.0.x CVEs
CVE
Severity
Description
Category
Affected
CVE-2024-23672
2024-01-19
0.0
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98. Users are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue.
data
operational
CWE-459
Details
CVE-2024-24549
2024-01-25
0.0
Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers had been processed.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98. Users are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue.
data
operational
CWE-20
Details
CVE-2024-21733
2024-01-01
3.1
Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43. Users are recommended to upgrade to version 8.5.64 onwards or 9.0.44 onwards, which contain a fix for the issue.
data
operational
CWE-209
Details
CVE-2023-46589
2023-10-23
7.5
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers. A trailer header that exceeded the header size limit could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Users are recommended to upgrade to version 11.0.0-M11 onwards, 10.1.16 onwards, 9.0.83 onwards or 8.5.96 onwards, which fix the issue.
data
operational
CWE-444
Details
CVE-2023-45648
2023-10-10
7.5
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially crafted, invalid trailer header could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fix the issue.
data
operational
CWE-20
Details
Most Critical Apache Tomcat 10.0.x CVEs
CVE
Severity
Description
Category
Affected
CVE-2022-42252
2022-10-03
7.5
If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header.
data
operational
CWE-444
Details
CVE-2023-46589
2023-10-23
7.5
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers. A trailer header that exceeded the header size limit could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Users are recommended to upgrade to version 11.0.0-M11 onwards, 10.1.16 onwards, 9.0.83 onwards or 8.5.96 onwards, which fix the issue.
data
operational
CWE-444
Details
CVE-2023-45648
2023-10-10
7.5
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially crafted, invalid trailer header could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fix the issue.
data
operational
CWE-20
Details
CVE-2021-42340
2021-10-13
7.5
The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError.
data
CWE-772
Details
CVE-2021-41079
2021-09-15
7.5
Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinite loop resulting in a denial of service.
configuration
data
operational
CWE-20
Details
What We Deliver
Migration support
Production & Development support
1 hr response-time
Unlimited support incidents
5 languages supported
Fast bug fixes & security patch turnaround
Enterprise Support Details
Subscription Level
Bronze
Silver
Gold
Core Count
64 cores
120 cores
248 cores
Apache Tomcat
✓
✓
✓
Apache TomEE
✓
✓
✓
Apache ActiveMQ
✓
✓
✓
Tribestream API Gateway
✓
✓
✓
SLA
24x7
24x7
24x7
Response Time
1hr
1hr
1hr
Incidents
unlimited
unlimited
unlimited
CVE Patching
unlimited
unlimited
unlimited
Developer Questions
1 parallel
2 parallel
4 parallel
Admin Contacts
2
3
4
Phone, Email, Portal
✓
✓
✓
Professional Services
3 days
5 days
10 days
Training
2 days
3 days
5 days
Feature Development
10 days
17 days
25 days
Close Menu
Binary Subscriptions
TomEE for Oracle Insurance Policy Administration Suite
TomEE for OpenText Web Experience Management
TomEE for OpenText Process Suite Platform
TomEE for OpenText AppWorks Platform
TomEE for Dassault Systemes SIMULIA Isight
TomEE for Dassault Systemes 3DEXPERIENCE Platform
Tomcat for Dassault Systemes ENOVIA
Tomcat for Progress OpenEdge
Support Subscriptions
Apache TomEE Support
Apache ActiveMQ Support
Apache Tomcat Support
CVE Patching
Enterprise Support
Tomitribe Community Partnership Program
CVE Index
Resources
Blog
Case Studies & Reports
Tribe’s Videos
Company
About Tomitribe
Community
Contact Us
Login
Get A Quote
twitter
facebook
linkedin
youtube
github