Published on: 18 December 2024
The Apache Software Foundation released security updates to address the vulnerabilities in the Apache Tomcat. A remote attacker could exploit the vulnerabilities by sending a specially crafted request to the affected systems.
For detailed information of the affected systems, please refer to the corresponding security advisory at software provider's website.
Successful exploitation of the vulnerabilities could lead to remote code execution or denial of service on an affected system.
The Apache Software Foundation has released new versions of the software to address the issue and they can be downloaded at the following URLs:
https://tomcat.apache.org/download-11.cgi#11.0.2
https://tomcat.apache.org/download-10.cgi#10.1.34
https://tomcat.apache.org/download-90.cgi#9.0.98