Korean
<< Back
VID 22956
Severity 30
Port 80, ...
Protocol TCP
Class WWW
Detailed Description The version of Tomcat installed on the remote host is prior to 9.0.37. It is, therefore, affected by multiple vulnerabilities as referenced in the fixed_in_apache_tomcat_9.0.37_security-9 advisory. Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

* References:
https://github.com/apache/tomcat/commit/40fa74c74822711ab878079d0a69f7357926723d
https://github.com/apache/tomcat/commit/172977f04a5215128f1e278a688983dcd230f399
https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.37

* Platforms Affected:
Apache Tomcat Server versions 9.0.x prior to 9.0.37
Any operating system Any version
Recommendation Upgrade to the latest version of Apache Tomcat Server (9.0.37 or later), available from the Apache Software Foundation download site, http://tomcat.apache.org/
Related URL CVE-2020-13934,CVE-2020-13935 (CVE)
Related URL (SecurityFocus)
Related URL (ISS)