Skip to content
COOEY

FAIL › dossier

Tomcat

PRODUCT

· dossier confidence 20%

Apache Tomcat, a widely used Java servlet container, has a history of critical remote code execution vulnerabilities, requiring diligent patching and security practices to mitigate risk. The product is currently supported until March 2027, but older versions have reached end-of-life.

PROFILE
CategorySoftwareWhat they doApache Tomcat is an open-source Java servlet container that implements the Java EE specification and provides a runtime environment for Java web applications. It is widely used for deploying web applications and services. Websitehttps://tomcat.apache.org/ ↗
SECURITY POSTURE

Apache Tomcat has a history of critical remote code execution vulnerabilities, indicating a potential for significant security risks if not properly patched and managed. The repeated occurrence of RCE vulnerabilities suggests a need for rigorous security practices and proactive vulnerability management.

Notable failures
  • CVE-2017-12615 (RCE)
  • CVE-2025-24813 (RCE)
  • CVE-2016-8735 (RCE)
  • CVE-2017-12617 (RCE)
  • CVE-2020-1938 (AJP trust issue)
Patterns: Repeated critical remote code execution (RCE) vulnerabilities; Vulnerabilities related to uploaded JSP files; Vulnerabilities related to Java Management Extension (JMX); Trust issues with AJP connections
FAILURE HISTORY · 8
DATEEVENTSEVSUMMARY
2022-03-25 CVE-2017-12615 critical Apache Tomcat on Windows allowed arbitrary code execution via uploaded JSP files when HTTP PUT was enabled.
2022-03-25 CVE-2017-12617 high Apache Tomcat allowed attackers to upload and execute arbitrary JSP files, enabling remote code execution.
2022-03-03 CVE-2020-1938 high An improperly managed privilege escalation in Apache Tomcat allowed attackers to bypass trust boundaries via AJP connections, leading to remote code execution.
2026-08-04 CVE-2026-34486 high Apache Tomcat missing encryption of sensitive data allows bypass of EncryptInterceptor.
2023-05-12 CVE-2016-8735 high Apache Tomcat remote code execution vulnerability exposed
2025-04-01 CVE-2025-24813 high Apache Tomcat's path equivalence vulnerability allows remote code execution via partial PUT requests, currently being actively exploited in the wild.
2020-02-24 CVE-2020-1938 critical CVE-2020-1938: When using the Apache JServ Protocol (AJP), care must be taken when trusting inc
2017-04-06 CVE-2016-8735 critical CVE-2016-8735: Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7
Open questions: What is the current development and maintenance model for Tomcat? · What are the specific coding practices contributing to the recurring RCE vulnerabilities?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-21 05:57:29.665967+00:00