9
Multiple vulnerabilities were identified in Apache products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, spoofing and security restriction bypass on the targeted system.
Impact
- Denial of Service
- Security Restriction Bypass
- Spoofing
System / Technologies affected
- Apache Tomcat versions from 9.0.0.M1 to 9.0.109
- Apache Tomcat versions from 10.1.0-M1 to 10.1.46
- Apache Tomcat versions from 11.0.0-M1 to 11.0.11
Solutions
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
- Update to Apache Tomcat version 9.0.110 or later
- Update to Apache Tomcat version 10.1.47 or later
- Update to Apache Tomcat version 11.0.12 or later