<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:22:59 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-03686</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-03686</link>
      <description>bdu:2021-03686</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-03686</guid>
    </item>
    <item>
      <title>BIT-tomcat-2021-30640 — Auth weakness in JNDIRealm</title>
      <link>https://cve.radiocsirt.org/vuln/bit-tomcat-2021-30640</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: tomcat&lt;/p&gt;
&lt;p&gt;A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0 to 10.0.5; 9.0.0 to 9.0.45; 8.5.0 to 8.5.65.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: tomcat&lt;/p&gt;
&lt;p&gt;A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0 to 10.0.5; 9.0.0 to 9.0.45; 8.5.0 to 8.5.65.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-tomcat-2021-30640</guid>
    </item>
    <item>
      <title>EUVD-2026-27017</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-27017</link>
      <description>EUVD-2026-27017</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-27017</guid>
    </item>
    <item>
      <title>fkie_cve-2021-30640</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-30640</link>
      <description>&lt;p&gt;A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-30640</guid>
    </item>
    <item>
      <title>GHSA-36qh-35cm-5w2w — Authentication Bypass by Alternate Name in Apache Tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-36qh-35cm-5w2w</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat:tomcat&lt;/p&gt;
&lt;p&gt;A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat:tomcat&lt;/p&gt;
&lt;p&gt;A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-36qh-35cm-5w2w</guid>
    </item>
    <item>
      <title>gsd-2021-30640</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-30640</link>
      <description>gsd-2021-30640</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-30640</guid>
    </item>
    <item>
      <title>OESA-2021-1299 — tomcat security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1299</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: tomcat, openEuler:20.03-LTS-SP2: tomcat&lt;/p&gt;
&lt;p&gt;The Apache Tomcat software is developed in an open and participatory environment and released under the Apache License version 2. The Apache Tomcat project is intended to be a collaboration of the best-of-breed developers from around the world. We invite you to participate in this open development project&#13;
&#13;
Security Fix(es):&#13;
&#13;
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.(CVE-2021-30640)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: tomcat, openEuler:20.03-LTS-SP2: tomcat&lt;/p&gt;
&lt;p&gt;The Apache Tomcat software is developed in an open and participatory environment and released under the Apache License version 2. The Apache Tomcat project is intended to be a collaboration of the best-of-breed developers from around the world. We invite you to participate in this open development project&#13;
&#13;
Security Fix(es):&#13;
&#13;
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.(CVE-2021-30640)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1299</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:1490-1 — Security update for tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:1490-1</link>
      <description>&lt;p&gt;Security update for tomcat&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for tomcat&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:1490-1</guid>
    </item>
    <item>
      <title>RHSA-2021:4861 — Red Hat Security Advisory: Red Hat JBoss Web Server 5.6.0 Security release</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:4861</link>
      <description>&lt;p&gt;openssl: Read buffer overruns processing ASN.1 strings openssl: integer overflow in CipherUpdate openssl: NULL pointer dereference in X509_issuer_and_serial_hash() tomcat: JNDI realm authentication weakness tomcat: HTTP request smuggling when used with a reverse proxy tomcat: OutOfMemoryError caused by HTTP upgrade connection leak could lead to DoS&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;openssl: Read buffer overruns processing ASN.1 strings openssl: integer overflow in CipherUpdate openssl: NULL pointer dereference in X509_issuer_and_serial_hash() tomcat: JNDI realm authentication weakness tomcat: HTTP request smuggling when used with a reverse proxy tomcat: OutOfMemoryError caused by HTTP upgrade connection leak could lead to DoS&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:4861</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:3602-1 — Security update for tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:3602-1</link>
      <description>&lt;p&gt;Security update for tomcat&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for tomcat&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:3602-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-30640</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-30640</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: tomcat6, Ubuntu:Pro:14.04:LTS: tomcat7, Ubuntu:Pro:16.04:LTS: tomcat8, Ubuntu:Pro:16.04:LTS: tomcat7, Ubuntu:18.04:LTS: tomcat9, Ubuntu:Pro:18.04:LTS: tomcat8, Ubuntu:20.04:LTS: tomcat9&lt;/p&gt;
&lt;p&gt;A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: tomcat6, Ubuntu:Pro:14.04:LTS: tomcat7, Ubuntu:Pro:16.04:LTS: tomcat8, Ubuntu:Pro:16.04:LTS: tomcat7, Ubuntu:18.04:LTS: tomcat9, Ubuntu:Pro:18.04:LTS: tomcat8, Ubuntu:20.04:LTS: tomcat9&lt;/p&gt;
&lt;p&gt;A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-30640</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0607 — Red Hat FUSE: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0607</link>
      <description>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat FUSE ausnutzen, um vertrauliche Informationen offenzulegen, beliebigen Code auszuführen, einen Denial of Service Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, Daten und Informationen zu manipulieren und seine Privilegien zu erweitern.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat FUSE ausnutzen, um vertrauliche Informationen offenzulegen, beliebigen Code auszuführen, einen Denial of Service Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, Daten und Informationen zu manipulieren und seine Privilegien zu erweitern.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0607</guid>
    </item>
  </channel>
</rss>
