{"api_version":"v1","generated_at":"2026-10-05T11:50:00+00:00","product":{"cve_count":7,"evidence_gap_note":"This CVE identity is linked to an existing Lifecycle product history.","id":"security:cve-apache-tomcat-9b68bf24afdd","lifecycle_state":"covered","linked_lifecycle_url":"https://lifecycle.blacktree.nl/targets/tomcat","name":"Tomcat","next_cursor":null,"observations":[{"affected":"Apache Tomcat: 11.0.20, 10.1.53, 9.0.116","affected_versions_present":true,"cve_id":"CVE-2026-34486","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34486","fixed":"RHSA-2026:39188: Red Hat JBoss Web Server 7.0 on RHEL 10, Red Hat JBoss Web Server 7.0 on RHEL 8, Red Hat JBoss Web Server 7.0 on RHEL 9","last_modified":"2026-09-21T19:43:41.203Z","patch_url":"https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly","primary_source":"","published":"2026-04-09T19:35:35.994Z"},{"affected":"Apache Tomcat: 11.0.0-M1 \u2264 11.0.2, 10.1.0-M1 \u2264 10.1.34, 9.0.0.M1 \u2264 9.0.98, 8.5.0 \u2264 8.5.100, 3 < 8.5.0, 10.0.0-M1 \u2264 10.0.27","affected_versions_present":true,"cve_id":"CVE-2025-24813","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-24813","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2025-10-29T11:49:44.413Z","patch_url":"https://access.redhat.com/security/cve/CVE-2025-24813","primary_source":"","published":"2025-03-10T16:44:03.715Z"},{"affected":"Apache Tomcat: Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50, 7.0.0 to 7.0.99","affected_versions_present":true,"cve_id":"CVE-2020-1938","cve_url":"https://cve.blacktree.nl/cve/CVE-2020-1938","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-10-21T23:35:50.835Z","patch_url":"https://lists.apache.org/thread.html/rd0774c95699d5aeb5e16e9a600fb2ea296e81175e30a62094e27e3e7%40%3Ccommits.ofbiz.apache.org%3E","primary_source":"","published":"2020-02-24T21:19:18.000Z"},{"affected":"9.0.0.M1 to 9.0.17; 8.5.0 to 8.5.39; 7.0.0 to 7.0.93","affected_versions_present":true,"cve_id":"CVE-2019-0232","cve_url":"https://cve.blacktree.nl/cve/CVE-2019-0232","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-04T17:44:15.941Z","patch_url":"","primary_source":"","published":"2019-04-15T14:23:52.000Z"},{"affected":"Apache Tomcat: 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46, 7.0.0 to 7.0.81","affected_versions_present":true,"cve_id":"CVE-2017-12617","cve_url":"https://cve.blacktree.nl/cve/CVE-2017-12617","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-10-21T23:55:32.381Z","patch_url":"http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html","primary_source":"","published":"2017-10-03T15:00:00.000Z"},{"affected":"Apache Tomcat: 7.0.0 to 7.0.79","affected_versions_present":true,"cve_id":"CVE-2017-12615","cve_url":"https://cve.blacktree.nl/cve/CVE-2017-12615","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-08-06T03:55:30.740Z","patch_url":"https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3E","primary_source":"","published":"2017-09-19T13:00:00.000Z"},{"affected":"Apache Tomcat: before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, 9.x before 9.0.0.M12","affected_versions_present":true,"cve_id":"CVE-2016-8735","cve_url":"https://cve.blacktree.nl/cve/CVE-2016-8735","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-10-21T23:55:42.758Z","patch_url":"http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html","primary_source":"","published":"2017-04-06T21:00:00.000Z"}],"source_generated_at":"2026-10-05T06:20:29.126Z","vendor":"Apache"}}
