Search CVE reports


Toggle filters

91 – 92 of 92 results


CVE-2022-34305

Low priority
Vulnerable

In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS...

5 affected packages

tomcat6, tomcat7, tomcat10, tomcat8, tomcat9

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release Not in release Not in release Not in release Not in release
tomcat7 Not in release Not in release Not in release Not in release Not affected
tomcat10 Not affected Not affected Not in release Not in release Not in release
tomcat8 Not in release Not in release Not in release Not in release Not affected
tomcat9 Not affected Not affected Vulnerable Vulnerable Not affected
Show less packages

CVE-2022-29885

Low priority

Some fixes available 4 of 5

The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network....

5 affected packages

tomcat6, tomcat7, tomcat10, tomcat8, tomcat9

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release Not in release Not in release Not in release Not in release
tomcat7 Not in release Not in release Not in release Not in release Not affected
tomcat10 Not affected Not affected Not in release Not in release Not in release
tomcat8 — — — — Fixed
tomcat9 Not affected Not affected Fixed Fixed Fixed
Show less packages