Product overview
Apache Tomcat is tracked by BlackTree as a server-side software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.
Main capabilities
- Networked or application service delivery
- Administrative and operational interfaces
- Versioned maintenance and security updates
Typical use
Used to provide application, infrastructure or operational services to other systems and users.
Deployment
Deployed on servers, virtual machines, containers or managed infrastructure.
This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page ↗.
Collected lifecycle data
| Product | Apache Tomcat |
|---|
| Release | 2.3 |
|---|
| End of Retirement | 25 June 2009 |
|---|
| Date precision | Day |
|---|
Known exploited vulnerabilities
Catalogue updated 17 Sep 2026These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.
Apache · TomcatRansomware use: Unknown
CISA entry ↗Apache Tomcat Path Equivalence Vulnerability
Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request. This vulnerability can be chained with CVE‑2026‑34486.
Apache · TomcatRansomware use: Unknown
CISA entry ↗Apache Tomcat Remote Code Execution Vulnerability
Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn't updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types.
Apache · TomcatRansomware use: Unknown
CISA entry ↗Apache Tomcat Remote Code Execution Vulnerability
When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
Apache · TomcatRansomware use: Unknown
CISA entry ↗Apache Tomcat on Windows Remote Code Execution Vulnerability
When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
Apache · TomcatRansomware use: Known
CISA entry ↗Apache Tomcat Improper Privilege Management Vulnerability
Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited.
Apache · TomcatRansomware use: Unknown
CISA entry ↗
Package vulnerability advisories
Checked 16 Sep 2026OSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.
Apache Tomcat's DIGEST authenticator has an Authentication Bypass by Capture-replay vulnerability
pkg:maven/org.apache.tomcat/tomcatFixed: 11.0.25, 10.1.58, 9.0.121
OSV record ↗Apache Tomcat has an Improper Access Control, Incorrect Authorization vulnerability
pkg:maven/org.apache.tomcat/tomcatFixed: 11.0.25, 10.1.58, 9.0.121
OSV record ↗Apache Tomcat's FORM authentication process has an Incorrect Authorization vulnerability
pkg:maven/org.apache.tomcat/tomcatFixed: 11.0.25, 10.1.58, 9.0.121
OSV record ↗Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File
pkg:maven/org.apache.tomcat/tomcatFixed: 9.0.117, 10.1.54, 11.0.21
OSV record ↗Apache Tomcat has an Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve
pkg:maven/org.apache.tomcat/tomcatFixed: 9.0.116, 10.1.54, 11.0.21
OSV record ↗Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling
pkg:maven/org.apache.tomcat/tomcatFixed: 9.0.118, 10.1.55, 11.0.22
OSV record ↗Apache Tomcat - Client certificate verification bypass
pkg:maven/org.apache.tomcat/tomcatFixed: 11.0.15, 10.1.50, 9.0.113
OSV record ↗Apache Tomcat has an Open Redirect vulnerability
pkg:maven/org.apache.tomcat/tomcatFixed: 9.0.116, 10.1.53, 11.0.20
OSV record ↗
Source evidence
PRIMARYManual
Apache Tomcat official lifecycle source
Servlet Spec | Pages Spec | JDSOL Spec | EL Spec | WebSocket Spec | Authentication Spec (JASPIC) | Annotation Spec | Apache Tomcat Version | Final 1 Released Version | Supported Java Versions | EOL Date | 2.3 | 1.2 | N/A | N/A | N/A | N/A | N/A | 4.1.x (archived) | 4.1.40 (archived) | 1.3 and later | 2009-06-25
Publisher identity used by product-specific official-source collectors.
First collected 31 Aug 2026 · Last collected 12 Sep 2026 · Review state accepted
Open official vendor source ↗