VendorsApachetomcat7.0.19
Vulnerabilities

Apache Tomcat 7.0.19

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

42CVEs
CVE-2013-2071
java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request information intended for other applications in opportunistic circumstances via an application that records the requests that it processes.
Published 2013-06-01 · Modified
2.6EPSS 0.065
CVE-2013-0346
Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might allow local users to obtain sensitive information by reading a file. NOTE: One Tomcat distributor has stated "The tomcat log directory does not contain any sensitive information."
Published 2014-02-15 · Modified
2.1EPSS 0.007
← Prev2 / 2