<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:07:06.616008+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2020-01972</id>
    <title>bdu:2020-01972</title>
    <updated>2026-10-02T19:07:06.946143+00:00</updated>
    <content>bdu:2020-01972</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2020-01972"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2019-avi-643</id>
    <title>certfr-2019-avi-643 — De multiples vulnérabilités ont été découvertes dans Apache Tomcat.
Elles permettent à un attaquant de provoquer un con…</title>
    <updated>2026-10-02T19:07:06.946190+00:00</updated>
    <content>certfr-2019-avi-643</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2019-avi-643"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-00504</id>
    <title>cnvd-2020-00504</title>
    <updated>2026-10-02T19:07:06.946211+00:00</updated>
    <content>cnvd-2020-00504</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-00504"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-55038</id>
    <title>EUVD-2026-55038</title>
    <updated>2026-10-02T19:07:06.946224+00:00</updated>
    <content>EUVD-2026-55038</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-55038"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-12418</id>
    <title>fkie_cve-2019-12418</title>
    <updated>2026-10-02T19:07:06.946234+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-12418"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hh3j-x4mc-g48r</id>
    <title>GHSA-hh3j-x4mc-g48r — Insufficiently Protected Credentials in Apache Tomcat</title>
    <updated>2026-10-02T19:07:06.946265+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.tomcat.embed:tomcat-embed-core</p>
<p>When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hh3j-x4mc-g48r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-12418</id>
    <title>gsd-2019-12418</title>
    <updated>2026-10-02T19:07:06.946292+00:00</updated>
    <content>gsd-2019-12418</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-12418"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2020:0038-1</id>
    <title>openSUSE-SU-2020:0038-1 — Security update for tomcat</title>
    <updated>2026-10-02T19:07:06.946303+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for tomcat</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2020:0038-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:0860</id>
    <title>RHSA-2020:0860 — Red Hat Security Advisory: Red Hat JBoss Web Server 3.1 Service Pack 8 security update</title>
    <updated>2026-10-02T19:07:06.946323+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>tomcat: XSS in SSI printenv tomcat: local privilege escalation tomcat: Session fixation when using FORM authentication tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:0860"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2020:0029-1</id>
    <title>SUSE-SU-2020:0029-1 — Security update for tomcat</title>
    <updated>2026-10-02T19:07:06.946346+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for tomcat</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2020:0029-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-12418</id>
    <title>UBUNTU-CVE-2019-12418</title>
    <updated>2026-10-02T19:07:06.946362+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: tomcat7, Ubuntu:16.04:LTS: tomcat8, Ubuntu:Pro:16.04:LTS: tomcat7, Ubuntu:Pro:18.04:LTS: tomcat8, Ubuntu:Pro:18.04:LTS: tomcat9</p>
<p>When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-12418"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1229</id>
    <title>WID-SEC-W-2023-1229 — Apache Tomcat: Mehrere Schwachstellen</title>
    <updated>2026-10-02T19:07:06.946389+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen in Apache Tomcat ausnutzen, um Daten offenzulegen oder die Kontrolle über eine Tomcat-Instanz zu erlangen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1229"/>
  </entry>
</feed>
