KLA12087
Multiple vulnerabilities in Apache Tomcat

Updated: 02/16/2021
Detect date
?
11/17/2020
Severity
?
Warning
Description

Multiple vulnerabilities were found in Apache Tomcat. Malicious users can exploit these vulnerabilities to obtain sensitive information, spoof user interface.

Below is a complete list of vulnerabilities:

  1. An information disclosure vulnerability can be exploited to obtain sensitive information.
  2. A security UI vulnerability in HTTP/2 client can be exploited remotely to spoof user interface.
Affected products

Apache Tomcat 8.5.x earlier than 8.5.60
Apache Tomcat 9.x earlier than 9.0.40

Solution

Update to the latest version
Tomcat 8.5 Software Downloads
Tomcat 9 Software Downloads

Original advisories

Apache Tomcat 8.5.x vulnerabilities
Apache Tomcat 9.x vulnerabilities

Impacts
?
OSI 
[?]

SUI 
[?]
Related products
Apache Tomcat
CVE-IDS
?
CVE-2021-241224.3Warning
CVE-2020-175275.0Critical