First published: Tue Jul 14 2020(Updated: )
A flaw was found in Apache Tomcat, where the payload length in a WebSocket frame was not correctly validated. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service. The highest threat from this vulnerability is to system availability.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/tomcat | <0:7.0.76-15.el7 | 0:7.0.76-15.el7 |
redhat/jbossweb | <0:7.5.31-2.Final_redhat_2.1.ep6.el5 | 0:7.5.31-2.Final_redhat_2.1.ep6.el5 |
redhat/jbossweb | <0:7.5.31-2.Final_redhat_2.1.ep6.el6 | 0:7.5.31-2.Final_redhat_2.1.ep6.el6 |
redhat/jboss-as-appclient | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jbossas-appclient | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jbossas-bundles | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-cli | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-client-all | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-clustering | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-cmp | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-configadmin | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-connector | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-controller | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-controller-client | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jbossas-core | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-core-security | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-deployment-repository | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-deployment-scanner | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jbossas-domain | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-domain-http | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-domain-management | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-ee | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-ee-deployment | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-ejb3 | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-embedded | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-host-controller | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-jacorb | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jbossas-javadocs | <0:7.5.24-1.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-1.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-jaxr | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-jaxrs | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-jdr | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-jmx | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-jpa | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-jsf | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-jsr77 | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-logging | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-mail | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-management-client-content | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-messaging | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-modcluster | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jbossas-modules-eap | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-naming | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-network | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-osgi | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-osgi-configadmin | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-osgi-service | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-picketlink | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-platform-mbean | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-pojo | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-process-controller | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jbossas-product-eap | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-protocol | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-remoting | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-sar | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-security | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-server | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jbossas-standalone | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-system-jmx | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-threads | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-transactions | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-version | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-web | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-webservices | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jbossas-welcome-content-eap | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-weld | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jboss-as-xts | <0:7.5.24-2.Final_redhat_00001.1.ep6.el6 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el6 |
redhat/jbossts | <1:4.17.45-2.Final_redhat_2.1.ep6.el6 | 1:4.17.45-2.Final_redhat_2.1.ep6.el6 |
redhat/jbossweb | <0:7.5.32-2.Final_redhat_1.2.ep6.el6 | 0:7.5.32-2.Final_redhat_1.2.ep6.el6 |
redhat/jbossweb | <0:7.5.31-2.Final_redhat_2.1.ep6.el7 | 0:7.5.31-2.Final_redhat_2.1.ep6.el7 |
redhat/jboss-as-appclient | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-appclient | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-bundles | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-cli | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-client-all | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-clustering | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-cmp | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-configadmin | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-connector | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-controller | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-controller-client | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-core | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-core-security | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-deployment-repository | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-deployment-scanner | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-domain | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-domain-http | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-domain-management | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-ee | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-ee-deployment | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-ejb3 | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-embedded | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-host-controller | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-jacorb | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-javadocs | <0:7.5.24-1.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-1.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-jaxr | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-jaxrs | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-jdr | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-jmx | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-jpa | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-jsf | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-jsr77 | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-logging | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-mail | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-management-client-content | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-messaging | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-modcluster | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-modules-eap | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-naming | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-network | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-osgi | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-osgi-configadmin | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-osgi-service | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-picketlink | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-platform-mbean | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-pojo | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-process-controller | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-product-eap | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-protocol | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-remoting | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-sar | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-security | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-server | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-standalone | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-system-jmx | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-threads | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-transactions | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-version | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-web | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-webservices | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-welcome-content-eap | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-weld | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-xts | <0:7.5.24-2.Final_redhat_00001.1.ep6.el7 | 0:7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossts | <1:4.17.45-2.Final_redhat_2.1.ep6.el7 | 1:4.17.45-2.Final_redhat_2.1.ep6.el7 |
redhat/jbossweb | <0:7.5.32-2.Final_redhat_1.2.ep6.el7 | 0:7.5.32-2.Final_redhat_1.2.ep6.el7 |
redhat/tomcat7 | <0:7.0.70-41.ep7.el6 | 0:7.0.70-41.ep7.el6 |
redhat/tomcat8 | <0:8.0.36-45.ep7.el6 | 0:8.0.36-45.ep7.el6 |
redhat/tomcat7 | <0:7.0.70-41.ep7.el7 | 0:7.0.70-41.ep7.el7 |
redhat/tomcat8 | <0:8.0.36-45.ep7.el7 | 0:8.0.36-45.ep7.el7 |
redhat/jws5-tomcat | <0:9.0.30-5.redhat_6.1.el6 | 0:9.0.30-5.redhat_6.1.el6 |
redhat/jws5-tomcat | <0:9.0.30-5.redhat_6.1.el7 | 0:9.0.30-5.redhat_6.1.el7 |
redhat/jws5-tomcat | <0:9.0.30-5.redhat_6.1.el8 | 0:9.0.30-5.redhat_6.1.el8 |
redhat/tomcat | <10.0.0 | 10.0.0 |
redhat/tomcat | <9.0.37 | 9.0.37 |
redhat/tomcat | <8.5.57 | 8.5.57 |
redhat/tomcat | <7.0.105 | 7.0.105 |
maven/org.apache.tomcat:tomcat | >=7.0.27<7.0.105 | 7.0.105 |
maven/org.apache.tomcat:tomcat | >=8.5.0<8.5.57 | 8.5.57 |
maven/org.apache.tomcat:tomcat | >=9.0.0.M1<9.0.37 | 9.0.37 |
maven/org.apache.tomcat:tomcat | >=10.0.0-M1<10.0.0-M7 | 10.0.0-M7 |
Apache Tomcat | >=7.0.27<=7.0.104 | |
Apache Tomcat | >=8.5.0<=8.5.56 | |
Apache Tomcat | >=9.0.1<=9.0.36 | |
Apache Tomcat | =9.0.0-milestone1 | |
Apache Tomcat | =9.0.0-milestone10 | |
Apache Tomcat | =9.0.0-milestone11 | |
Apache Tomcat | =9.0.0-milestone12 | |
Apache Tomcat | =9.0.0-milestone13 | |
Apache Tomcat | =9.0.0-milestone14 | |
Apache Tomcat | =9.0.0-milestone15 | |
Apache Tomcat | =9.0.0-milestone16 | |
Apache Tomcat | =9.0.0-milestone17 | |
Apache Tomcat | =9.0.0-milestone18 | |
Apache Tomcat | =9.0.0-milestone19 | |
Apache Tomcat | =9.0.0-milestone2 | |
Apache Tomcat | =9.0.0-milestone20 | |
Apache Tomcat | =9.0.0-milestone21 | |
Apache Tomcat | =9.0.0-milestone22 | |
Apache Tomcat | =9.0.0-milestone23 | |
Apache Tomcat | =9.0.0-milestone24 | |
Apache Tomcat | =9.0.0-milestone25 | |
Apache Tomcat | =9.0.0-milestone26 | |
Apache Tomcat | =9.0.0-milestone27 | |
Apache Tomcat | =9.0.0-milestone3 | |
Apache Tomcat | =9.0.0-milestone4 | |
Apache Tomcat | =9.0.0-milestone5 | |
Apache Tomcat | =9.0.0-milestone6 | |
Apache Tomcat | =9.0.0-milestone7 | |
Apache Tomcat | =9.0.0-milestone8 | |
Apache Tomcat | =9.0.0-milestone9 | |
Apache Tomcat | =10.0.0-milestone1 | |
Apache Tomcat | =10.0.0-milestone2 | |
Apache Tomcat | =10.0.0-milestone3 | |
Apache Tomcat | =10.0.0-milestone4 | |
Apache Tomcat | =10.0.0-milestone5 | |
Apache Tomcat | =10.0.0-milestone6 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
NetApp OnCommand System Manager | >=3.0.0<=3.1.3 | |
openSUSE Leap | =15.1 | |
openSUSE Leap | =15.2 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =20.04 | |
McAfee ePolicy Orchestrator | =5.9.0 | |
McAfee ePolicy Orchestrator | =5.9.1 | |
McAfee ePolicy Orchestrator | =5.10.0 | |
McAfee ePolicy Orchestrator | =5.10.0-update_1 | |
McAfee ePolicy Orchestrator | =5.10.0-update_2 | |
McAfee ePolicy Orchestrator | =5.10.0-update_3 | |
McAfee ePolicy Orchestrator | =5.10.0-update_4 | |
McAfee ePolicy Orchestrator | =5.10.0-update_5 | |
McAfee ePolicy Orchestrator | =5.10.0-update_6 | |
McAfee ePolicy Orchestrator | =5.10.0-update_7 | |
McAfee ePolicy Orchestrator | =5.10.0-update_8 | |
Oracle Agile Engineering Data Management | =6.2.1.0 | |
Oracle Agile PLM | =9.3.3 | |
Oracle Agile PLM | =9.3.5 | |
Oracle Agile PLM | =9.3.6 | |
Oracle Blockchain Platform | <21.1.2 | |
Oracle Commerce Guided Search | =11.3.2 | |
Oracle Communications Cloud Native Core Policy | =1.14.0 | |
Oracle Communications Instant Messaging Server | =10.0.1.5.0 | |
Oracle Fmw Platform | =12.2.1.3.0 | |
Oracle Fmw Platform | =12.2.1.4.0 | |
Oracle Instantis Enterprisetrack | =17.1 | |
Oracle Instantis Enterprisetrack | =17.2 | |
Oracle Instantis Enterprisetrack | =17.3 | |
Oracle Managed File Transfer | =12.2.1.3.0 | |
Oracle Managed File Transfer | =12.2.1.4.0 | |
Oracle Mysql Enterprise Monitor | <=8.0.21 | |
Oracle Siebel Ui Framework | <=20.12 | |
Oracle Workload Manager | =12.2.0.1 | |
Oracle Workload Manager | =18c | |
Oracle Workload Manager | =19c | |
debian/tomcat9 | 9.0.43-2~deb11u10 9.0.70-2 9.0.95-1 |
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)