Linuxsecurity Debian Releases Security Advisories for Tomcat9, Tomcat10, and Tomcat11 Vulnerabilities
Article Content
- •Debian released critical advisories for Tomcat9, Tomcat10, and Tomcat11 vulnerabilities.
- •Tomcat9 and Tomcat10 vulnerabilities involve authentication bypass and denial-of-service risks.
- •Users are advised to upgrade to the latest versions to mitigate security risks.
Debian has issued critical security advisories for Tomcat9, Tomcat10, and Tomcat11 addressing various vulnerabilities. Tomcat9 (DLA-4619) fixed an authentication bypass and denial-of-service issue in version 9.0.118-0+deb11u1. Tomcat10 (DSA-6328) addressed a similar critical denial-of-service vulnerability in versions 10.1.55-1~deb12u1 for oldstable and 10.1.55-1~deb13u1 for stable. Tomcat11 (DSA-6329) resolved a moderate DDoS vulnerability in version 11.0.22-1~deb13u1. All advisories recommend upgrading affected packages and consulting the respective documentation for further details. The vulnerabilities may introduce new options or limits that could impact existing web applications. Users are urged to apply updates promptly to mitigate potential risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Debian in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…