FAIL › dossier
Tomcat
PRODUCT· dossier confidence 20%
Apache Tomcat, a widely used Java servlet container, has a history of critical remote code execution vulnerabilities, requiring diligent patching and security practices to mitigate risk. The product is currently supported until March 2027, but older versions have reached end-of-life.
PROFILE
CategorySoftwareWhat they doApache Tomcat is an open-source Java servlet container that implements the Java EE specification and provides a runtime environment for Java web applications. It is widely used for deploying web applications and services.
Websitehttps://tomcat.apache.org/ ↗
SECURITY POSTURE
Apache Tomcat has a history of critical remote code execution vulnerabilities, indicating a potential for significant security risks if not properly patched and managed. The repeated occurrence of RCE vulnerabilities suggests a need for rigorous security practices and proactive vulnerability management.
Notable failures
- CVE-2017-12615 (RCE)
- CVE-2025-24813 (RCE)
- CVE-2016-8735 (RCE)
- CVE-2017-12617 (RCE)
- CVE-2020-1938 (AJP trust issue)
Patterns: Repeated critical remote code execution (RCE) vulnerabilities; Vulnerabilities related to uploaded JSP files; Vulnerabilities related to Java Management Extension (JMX); Trust issues with AJP connections
FAILURE HISTORY · 8
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-03-25 | CVE-2017-12615 | critical | Apache Tomcat on Windows allowed arbitrary code execution via uploaded JSP files when HTTP PUT was enabled. |
| 2022-03-25 | CVE-2017-12617 | high | Apache Tomcat allowed attackers to upload and execute arbitrary JSP files, enabling remote code execution. |
| 2022-03-03 | CVE-2020-1938 | high | An improperly managed privilege escalation in Apache Tomcat allowed attackers to bypass trust boundaries via AJP connections, leading to remote code execution. |
| 2026-08-04 | CVE-2026-34486 | high | Apache Tomcat missing encryption of sensitive data allows bypass of EncryptInterceptor. |
| 2023-05-12 | CVE-2016-8735 | high | Apache Tomcat remote code execution vulnerability exposed |
| 2025-04-01 | CVE-2025-24813 | high | Apache Tomcat's path equivalence vulnerability allows remote code execution via partial PUT requests, currently being actively exploited in the wild. |
| 2020-02-24 | CVE-2020-1938 | critical | CVE-2020-1938: When using the Apache JServ Protocol (AJP), care must be taken when trusting inc |
| 2017-04-06 | CVE-2016-8735 | critical | CVE-2016-8735: Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7 |
DOSSIER SOURCES
- Yamazen (TYO:8051) Company Profile & Description - Stock Analysis · stockanalysis.com
- GameStop (GME) Company Profile & Description - Stock Analysis · stockanalysis.com
- Critical Apache Tomcat Flaw Actively Exploited in Attacks · dailysecurityreview.com
- Vulnerability - cert-in.org.in · www.cert-in.org.in
- CVE-2026-59083: Apache Tomcat Auth Bypass Vulnerability - SentinelOne · SentinelOne
- Tomcat: Releases, patches & end-of-life - versio.io · www.versio.io
- Apache Tomcat end-of-life dates & support status (2026) | IsItPatched · www.isitpatched.com
- Tomcat: Releases, patches & end-of-life - versio.io · www.versio.io
Open questions: What is the current development and maintenance model for Tomcat? · What are the specific coding practices contributing to the recurring RCE vulnerabilities?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-21 05:57:29.665967+00:00