Maven package intelligence

org.apache.tomcat:tomcat-catalina Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the Maven package org.apache.tomcat:tomcat-catalina, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
3
Known exploited vulnerabilities affecting org.apache.tomcat:tomcat-catalina
In CISA KEV
3
Records also listed in the official catalog
Beyond CISA KEV
0
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
0
org.apache.tomcat:tomcat-catalina KEVs with sensor-observed exploitation activity

Review org.apache.tomcat:tomcat-catalina exploitation against the versions you run

All three exploited org.apache.tomcat:tomcat-catalina vulnerabilities tracked here are also listed in CISA KEV.

100%
Covered by CISA
0%
Beyond CISA

Attested org.apache.tomcat:tomcat-catalina vulnerabilities

3 known exploited vulnerabilities affecting this package.

Vulnerability CISA KEV Added
CVE-2017-12617

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via...

In CISA 25 Mar 2022
CVE-2016-8735

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before...

In CISA 12 May 2023
CVE-2025-24813

Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT

In CISA 01 Apr 2025

Recurring weakness patterns

Unrestricted Upload of File with Dangerous Type, Path Equivalence: 'file.name' (Internal Dot), and Deserialization of Untrusted Data account for mapped occurrences across this org.apache.tomcat:tomcat-catalina KEV portfolio.

Browse all KEVs →