Popis
Multiple vulnerabilities were found in Apache Tomcat. Malicious users can exploit these vulnerabilities to obtain sensitive information, bypass security restrictions, execute arbitrary code.
Below is a complete list of vulnerabilities:
- Configured cipher preference order not preserved vulnerability in Apache Tomcat can be exploited to obtain sensitive information.
- Improper Input Validation vulnerability in Apache Tomcat can be exploited to bypass security restrictions.
- Security vulnerability can be exploited to bypass security restrictions.
- Padding Oracle vulnerability in Apache Tomcat can be exploited to obtain sensitive information.
- Occasional URL redirection to untrusted Site (‚Open Redirect‘) vulnerability in Apache Tomcat can be exploited to obtain sensitive information.
- Inconsistent Interpretation of HTTP Requests (‚HTTP Request/Response Smuggling‘) vulnerability in Apache Tomcat can be exploited to execute arbitrary code.
Oficiální doporučení
Vykořisťování
Public exploits exist for this vulnerability.
Související produkty
seznam CVE
- CVE-2026-24880 critical
- CVE-2026-25854 high
- CVE-2026-29129 critical
- CVE-2026-29145 critical
- CVE-2026-29146 critical
- CVE-2026-32990 high
Zobrazit více
Zjistěte statistiky zranitelností šířících se ve vaší oblasti statistics.securelist.com
Našli jste v popisu této chyby zabezpečení nepřesnost? Dej nám vědět!