Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
tomcat vulnerabilities and exploits
(subscribe to this query)
10
CVSSv2
CVE-2021-32588
A use of hard-coded credentials (CWE-798) vulnerability in FortiPortal versions 5.2.5 and below, 5.3.5 and below, 6.0.4 and below, versions 5.1.x and 5.0.x may allow a remote and unauthenticated malicious user to execute unauthorized commands as root by uploading and deploying ma...
Fortinet Fortiportal
10
CVSSv2
CVE-2013-4810
HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote malicious users to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet, aka ZDI-CAN-1760. N...
Hp Application Lifecycle Management -
Hp Procurve Manager 4.0
Hp Identity Driven Manager 4.0
Hp Procurve Manager 3.20
1 EDB exploit
10
CVSSv2
CVE-2013-1221
The Tomcat Web Management feature in Cisco Unified Customer Voice Portal (CVP) Software prior to 9.0.1 ES 11 does not properly configure Tomcat components, which allows remote malicious users to execute arbitrary code via a crafted (1) HTTP or (2) HTTPS request, aka Bug ID CSCub3...
Cisco Unified Customer Voice Portal 4.0\\(2\\)
Cisco Unified Customer Voice Portal 3.0
Cisco Unified Customer Voice Portal 8.0\\(1\\)
Cisco Unified Customer Voice Portal 3.6\\(10\\)
Cisco Unified Customer Voice Portal 8.5\\(1\\)
Cisco Unified Customer Voice Portal 4.0
Cisco Unified Customer Voice Portal 4.1
Cisco Unified Customer Voice Portal 7.0
Cisco Unified Customer Voice Portal 9.0
Cisco Unified Customer Voice Portal 7.0\\(2\\)
Cisco Unified Customer Voice Portal
10
CVSSv2
CVE-2010-0219
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote malicious users to execute arbitrary code by uploading a crafted web s...
Apache Axis2 1.3
Apache Axis2 1.4
Apache Axis2 1.5.2
Apache Axis2 1.6
Apache Axis2 1.5
Apache Axis2 1.4.1
Apache Axis2 1.5.1
Sap Businessobjects 3.2
3 EDB exploits
1 Github repository
10
CVSSv2
CVE-2010-0570
Cisco Digital Media Manager (DMM) 5.0.x and 5.1.x has a default password for the Tomcat administration account, which makes it easier for remote malicious users to execute arbitrary code via a crafted web application, aka Bug ID CSCta03378.
Cisco Digital Media Manager 5.0.1
Cisco Digital Media Manager 5.0.2
Cisco Digital Media Manager 5.0
Cisco Digital Media Manager 5.0.3
Cisco Digital Media Manager 5.1
10
CVSSv2
CVE-2009-4188
HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote malicious users to execute arbitrary code via a session that uses the manager role to conduct unrestricted file upload attacks against the /manager servlet in the Tomcat s...
Hp Operations Dashboard
2 EDB exploits
10
CVSSv2
CVE-2009-4189
HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote malicious users to execute arbitrary code via a session that uses the manager role to conduct unrestricted file upload attacks against the /manager servlet in the Tomcat servle...
Hp Operations Manager
1 EDB exploit
10
CVSSv2
CVE-2009-3843
HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote malicious users to conduct unrestricted file upload attacks, and thereby execute arbitrary code, by using the org.apache.catalina.manager.H...
Hp Operations Manager 8.10
1 EDB exploit
2 Github repositories
10
CVSSv2
CVE-2008-0457
Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, as used by Symantec Backup Exec System Recovery Manager 7.0 and 7.0.1, allows remote malicious users to upload and execute arbitrary JSP files via unknown vector...
Symantec Backupexec System Recovery 7.01
Symantec Backupexec System Recovery 7.0
2 EDB exploits
9.3
CVSSv2
CVE-2021-44228
Apache Log4j2 2.0-beta9 up to and including 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can contr...
Apache Log4j 2.0
Apache Log4j
Siemens Sppa-t3000 Ses3000 Firmware
Siemens Logo\\! Soft Comfort
Siemens Spectrum Power 4 4.70
Siemens Spectrum Power 4
Siemens Siveillance Control Pro
Siemens Energyip Prepay 3.7
Siemens Energyip Prepay 3.8
Siemens Siveillance Identity 1.6
Siemens Siveillance Identity 1.5
Siemens Siveillance Command
Siemens Sipass Integrated 2.85
Siemens Sipass Integrated 2.80
Siemens Head-end System Universal Device Integration System
Siemens Gma-manager
Siemens Energyip 8.5
Siemens Energyip 8.6
Siemens Energyip 8.7
Siemens Energyip 9.0
Siemens Energy Engage 3.1
Siemens E-car Operation Center
2 Metasploit modules
1137 Github repositories
28 Articles
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3012
CVE-2024-30200
XXE
CVE-2023-24955
CVE-2023-42931
CVE-2024-29231
remote code execution
cross-site scripting
CVE-2024-0677
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »