Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
AUTOMATICALLY VERIFIEDOFFICIAL VENDOR SOURCECOLLECTED 12 SEP 2026

Apache · AUTOMATIC DISCOVERY

Apache Tomcat 2.3

Apache Tomcat is tracked by BlackTree as a server-side software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Evidence status

This record passed BlackTree's automatic primary-source checks with a confidence score of 96. It is returned for operational research without requiring routine manual approval. Confirm edition and deployment applicability before acting.

Product overview

Apache Tomcat is tracked by BlackTree as a server-side software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Main capabilities

  • Networked or application service delivery
  • Administrative and operational interfaces
  • Versioned maintenance and security updates

Typical use

Used to provide application, infrastructure or operational services to other systems and users.

Deployment

Deployed on servers, virtual machines, containers or managed infrastructure.

This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page .

Collected lifecycle data

ProductApache Tomcat
Release2.3
End of Retirement25 June 2009
Date precisionDay

Known exploited vulnerabilities

Catalogue updated 17 Sep 2026

These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.

CVE-2026-34486Added 4 Aug 2026

Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.

Apache · TomcatRansomware use: Unknown

CISA entry
CVE-2025-24813Added 1 Apr 2025

Apache Tomcat Path Equivalence Vulnerability

Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request. This vulnerability can be chained with CVE‑2026‑34486.

Apache · TomcatRansomware use: Unknown

CISA entry
CVE-2016-8735Added 12 May 2023

Apache Tomcat Remote Code Execution Vulnerability

Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn't updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types.

Apache · TomcatRansomware use: Unknown

CISA entry
CVE-2017-12617Added 25 Mar 2022

Apache Tomcat Remote Code Execution Vulnerability

When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

Apache · TomcatRansomware use: Unknown

CISA entry
CVE-2017-12615Added 25 Mar 2022

Apache Tomcat on Windows Remote Code Execution Vulnerability

When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

Apache · TomcatRansomware use: Known

CISA entry
CVE-2020-1938Added 3 Mar 2022

Apache Tomcat Improper Privilege Management Vulnerability

Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited.

Apache · TomcatRansomware use: Unknown

CISA entry

Package vulnerability advisories

Checked 16 Sep 2026

OSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.

CVE-2026-65905Critical severity

Apache Tomcat's DIGEST authenticator has an Authentication Bypass by Capture-replay vulnerability

pkg:maven/org.apache.tomcat/tomcatFixed: 11.0.25, 10.1.58, 9.0.121

OSV record
CVE-2026-65182Critical severity

Apache Tomcat has an Improper Access Control, Incorrect Authorization vulnerability

pkg:maven/org.apache.tomcat/tomcatFixed: 11.0.25, 10.1.58, 9.0.121

OSV record
CVE-2026-68525Critical severity

Apache Tomcat's FORM authentication process has an Incorrect Authorization vulnerability

pkg:maven/org.apache.tomcat/tomcatFixed: 11.0.25, 10.1.58, 9.0.121

OSV record
CVE-2026-34487High severity

Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File

pkg:maven/org.apache.tomcat/tomcatFixed: 9.0.117, 10.1.54, 11.0.21

OSV record
CVE-2026-34483High severity

Apache Tomcat has an Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve

pkg:maven/org.apache.tomcat/tomcatFixed: 9.0.116, 10.1.54, 11.0.21

OSV record
CVE-2026-41284High severity

Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling

pkg:maven/org.apache.tomcat/tomcatFixed: 9.0.118, 10.1.55, 11.0.22

OSV record
CVE-2025-66614Medium severity

Apache Tomcat - Client certificate verification bypass

pkg:maven/org.apache.tomcat/tomcatFixed: 11.0.15, 10.1.50, 9.0.113

OSV record
CVE-2026-25854Medium severity

Apache Tomcat has an Open Redirect vulnerability

pkg:maven/org.apache.tomcat/tomcatFixed: 9.0.116, 10.1.53, 11.0.20

OSV record

Source evidence

PRIMARYManual

Apache Tomcat official lifecycle source

Servlet Spec | Pages Spec | JDSOL Spec | EL Spec | WebSocket Spec | Authentication Spec (JASPIC) | Annotation Spec | Apache Tomcat Version | Final 1 Released Version | Supported Java Versions | EOL Date | 2.3 | 1.2 | N/A | N/A | N/A | N/A | N/A | 4.1.x (archived) | 4.1.40 (archived) | 1.3 and later | 2009-06-25

Publisher identity used by product-specific official-source collectors.

First collected 31 Aug 2026 · Last collected 12 Sep 2026 · Review state accepted

Open official vendor source