Skip to main content

Apache Tomcat Multiple Vulnerabilities

Last Update Date: 24 Nov 2016 09:25 Release Date: 24 Nov 2016 2908 Views

RISK: Medium Risk

TYPE: Servers - Web Servers

TYPE: Web Servers

Multiple vulnerabilities were identified in Apache Tomcat, exploitation of these vulnerabilities can cause execution of arbitrary code, denial of service and obtain sensitive information.


Impact

  • Denial of Service
  • Remote Code Execution
  • Information Disclosure

System / Technologies affected

  • Apache Tomcat 9.0.0.M1 to 9.0.0.M11
  • Apache Tomcat 8.5.0 to 8.5.6
  • Apache Tomcat 8.0.0.RC1 to 8.0.38
  • Apache Tomcat 7.0.0 to 7.0.72
  • Apache Tomcat 6.0.0 to 6.0.47
  • Earlier, unsupported versions may also be affected.

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Upgrade to Apache Tomcat 9.0.0.M13 or later (Apache Tomcat 9.0.0.M12 has the fix but was not released)
  • Upgrade to Apache Tomcat 8.5.8 or later (Apache Tomcat 8.5.7 has the fix but was not released)
  • Upgrade to Apache Tomcat 8.0.39 or later
  • Upgrade to Apache Tomcat 7.0.73 or later
  • Upgrade to Apache Tomcat 6.0.48 or later

Vulnerability Identifier


Source


Related Link