Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
PRODUCT FAMILYSERVER APPLICATIONVERIFIED

Apache

Apache Tomcat

Apache Tomcat is tracked by BlackTree as a server-side software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Lifecycle status

No support or retirement date is shown unless BlackTree can link it to a registered publisher source. A missing date means that a boundary is not publicly stated, has not yet been extracted, or still needs source routing. It does not mean the product is supported indefinitely.

Product overview

Apache Tomcat is tracked by BlackTree as a server-side software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Main capabilities

  • Networked or application service delivery
  • Administrative and operational interfaces
  • Versioned maintenance and security updates

Typical use

Used to provide application, infrastructure or operational services to other systems and users.

Deployment

Deployed on servers, virtual machines, containers or managed infrastructure.

Lifecycle records

ReleaseBoundaryDate
2.2Retirement ends9 March 2004
2.3Retirement ends25 June 2009
2.5Retirement ends31 December 2016
3.0Retirement ends31 March 2021
5.0Retirement ends31 October 2022
3.1Retirement ends31 March 2024
Product policyEnd of support31 March 2027

Official sources

VERIFIED

Apache Tomcat official lifecycle source

Checked automatically.

Extracted 7 lifecycle record(s), including 7 bounded date record(s), from the registered official source.

Open publisher source

Package vulnerability advisories

Apache Tomcat's DIGEST authenticator has an Authentication Bypass by Capture-replay vulnerability

Fixed: 11.0.25, 10.1.58, 9.0.121

Apache Tomcat has an Improper Access Control, Incorrect Authorization vulnerability

Fixed: 11.0.25, 10.1.58, 9.0.121

Apache Tomcat's FORM authentication process has an Incorrect Authorization vulnerability

Fixed: 11.0.25, 10.1.58, 9.0.121

Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File

Fixed: 9.0.117, 10.1.54, 11.0.21

Apache Tomcat has an Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve

Fixed: 9.0.116, 10.1.54, 11.0.21

Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling

Fixed: 9.0.118, 10.1.55, 11.0.22

Apache Tomcat - Client certificate verification bypass

Fixed: 11.0.15, 10.1.50, 9.0.113

Apache Tomcat has an Open Redirect vulnerability

Fixed: 9.0.116, 10.1.53, 11.0.20