Maven package intelligence

org.apache.tomcat.embed:tomcat-embed-core Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the Maven package org.apache.tomcat.embed:tomcat-embed-core, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
5
Known exploited vulnerabilities affecting org.apache.tomcat.embed:tomcat-embed-core
In CISA KEV
5
Records also listed in the official catalog
Beyond CISA KEV
0
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
0
org.apache.tomcat.embed:tomcat-embed-core KEVs with sensor-observed exploitation activity

Review org.apache.tomcat.embed:tomcat-embed-core exploitation against the versions you run

All five exploited org.apache.tomcat.embed:tomcat-embed-core vulnerabilities tracked here are also listed in CISA KEV.

100%
Covered by CISA
0%
Beyond CISA

Attested org.apache.tomcat.embed:tomcat-embed-core vulnerabilities

5 known exploited vulnerabilities affecting this package.

Vulnerability CISA KEV Added
CVE-2020-1938

When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections...

In CISA 03 Mar 2022
CVE-2017-12615

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default...

In CISA 25 Mar 2022
CVE-2017-12617

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via...

In CISA 25 Mar 2022
CVE-2023-44487

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as...

In CISA 10 Oct 2023
CVE-2025-24813

Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT

In CISA 01 Apr 2025

Recurring weakness patterns

Unrestricted Upload of File with Dangerous Type, Uncontrolled Resource Consumption, and Path Equivalence: 'file.name' (Internal Dot) account for mapped occurrences across this org.apache.tomcat.embed:tomcat-embed-core KEV portfolio.

Browse all KEVs →