<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:57:38 +0000</lastBuildDate>
    <item>
      <title>bdu:2020-01972</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-01972</link>
      <description>bdu:2020-01972</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-01972</guid>
    </item>
    <item>
      <title>certfr-2019-avi-643 — De multiples vulnérabilités ont été découvertes dans Apache Tomcat.
Elles permettent à un attaquant de provoquer un con…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2019-avi-643</link>
      <description>certfr-2019-avi-643</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2019-avi-643</guid>
    </item>
    <item>
      <title>cnvd-2020-00504</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-00504</link>
      <description>cnvd-2020-00504</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-00504</guid>
    </item>
    <item>
      <title>EUVD-2026-55038</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-55038</link>
      <description>EUVD-2026-55038</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-55038</guid>
    </item>
    <item>
      <title>fkie_cve-2019-12418</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-12418</link>
      <description>&lt;p&gt;When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-12418</guid>
    </item>
    <item>
      <title>GHSA-hh3j-x4mc-g48r — Insufficiently Protected Credentials in Apache Tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hh3j-x4mc-g48r</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat.embed:tomcat-embed-core&lt;/p&gt;
&lt;p&gt;When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat.embed:tomcat-embed-core&lt;/p&gt;
&lt;p&gt;When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hh3j-x4mc-g48r</guid>
    </item>
    <item>
      <title>gsd-2019-12418</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-12418</link>
      <description>gsd-2019-12418</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-12418</guid>
    </item>
    <item>
      <title>openSUSE-SU-2020:0038-1 — Security update for tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2020:0038-1</link>
      <description>&lt;p&gt;Security update for tomcat&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for tomcat&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2020:0038-1</guid>
    </item>
    <item>
      <title>RHSA-2020:0860 — Red Hat Security Advisory: Red Hat JBoss Web Server 3.1 Service Pack 8 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:0860</link>
      <description>&lt;p&gt;tomcat: XSS in SSI printenv tomcat: local privilege escalation tomcat: Session fixation when using FORM authentication tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tomcat: XSS in SSI printenv tomcat: local privilege escalation tomcat: Session fixation when using FORM authentication tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:0860</guid>
    </item>
    <item>
      <title>SUSE-SU-2020:0029-1 — Security update for tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2020:0029-1</link>
      <description>&lt;p&gt;Security update for tomcat&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for tomcat&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2020:0029-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2019-12418</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-12418</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: tomcat7, Ubuntu:16.04:LTS: tomcat8, Ubuntu:Pro:16.04:LTS: tomcat7, Ubuntu:Pro:18.04:LTS: tomcat8, Ubuntu:Pro:18.04:LTS: tomcat9&lt;/p&gt;
&lt;p&gt;When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: tomcat7, Ubuntu:16.04:LTS: tomcat8, Ubuntu:Pro:16.04:LTS: tomcat7, Ubuntu:Pro:18.04:LTS: tomcat8, Ubuntu:Pro:18.04:LTS: tomcat9&lt;/p&gt;
&lt;p&gt;When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-12418</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1229 — Apache Tomcat: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1229</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Apache Tomcat ausnutzen, um Daten offenzulegen oder die Kontrolle über eine Tomcat-Instanz zu erlangen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Apache Tomcat ausnutzen, um Daten offenzulegen oder die Kontrolle über eine Tomcat-Instanz zu erlangen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1229</guid>
    </item>
  </channel>
</rss>
