[ All 3 A B C D E F G H I J K L M N O P Q R S T U V W X Y Z ]
×

Project tomcat-1:9.0.87-3.el9_6.1

Name tomcat
Epoch 1
Version 9.0.87
Release 3.el9_6.1
Website/URL http://tomcat.apache.org/
License ASL 2.0
Build Time 2025-07-17 09:05:01
Build Host builder-arm64-1.inferitos.ru
Summary Apache Servlet/JSP Engine, RI for Servlet 4.0/JSP 2.3 API
Repositories AppStream
Description Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world.
Errata INFSA-2025:11335
× Full screenshot
Found 1 old version
Packages link
Package Summary SHA-256 checksum
noarch
tomcat-1:9.0.87-3.el9_6.1.noarch Apache Servlet/JSP Engine, RI for Servlet 4.0/JSP 2.3 API 9d9bae977bc694508c35cb38119fdda83b48c0eaf8101cc5435821032fc73f43 download
tomcat-admin-webapps-1:9.0.87-3.el9_6.1.noarch The host-manager and manager web applications for Apache Tomcat c60416a0050b4bbac524d4f574fc8262157d0f5a79e22f6ce4d47ca481c66c29 download
tomcat-docs-webapp-1:9.0.87-3.el9_6.1.noarch The docs web application for Apache Tomcat a0b9e08961d356082c5b6d0cf0e8263544fb808eebdc36572306898565df00e8 download
tomcat-el-3.0-api-1:9.0.87-3.el9_6.1.noarch Apache Tomcat Expression Language v3.0 API Implementation Classes 004ce94b660387ef1cc4f5cf648ca406cc2522e8854860915c630338b53a26d0 download
tomcat-jsp-2.3-api-1:9.0.87-3.el9_6.1.noarch Apache Tomcat JavaServer Pages v2.3 API Implementation Classes 6bb570647ebfc0450bf3cc7e8e86c2c6abab9ed5760e18a9e51ae0e3dd17ac19 download
tomcat-lib-1:9.0.87-3.el9_6.1.noarch Libraries needed to run the Tomcat Web container 1f2bf8aac1fef1185bb58f7dea9b104842ef804999fa8ba1914edbce1bf1a0ef download
tomcat-servlet-4.0-api-1:9.0.87-3.el9_6.1.noarch Apache Tomcat Java Servlet v4.0 API Implementation Classes 7b8b094a202c34fc9decbba34c2f05c7230e079fda5136a0f8b2fc9f0ba85708 download
tomcat-webapps-1:9.0.87-3.el9_6.1.noarch The ROOT web application for Apache Tomcat af6eeadfa7d71c79f9cf1100ab3509f1f889a9456cda5a96309a4be96c892026 download
src
tomcat-1:9.0.87-3.el9_6.1.src Apache Servlet/JSP Engine, RI for Servlet 4.0/JSP 2.3 API 1a08a1366183a40f409abd9156d143d602cd76aa5d58026f475282a218c2805b download
Changelog link
* Mon May 26 2025 Adam Krajcik <akrajcik@redhat.com> - 1:9.0.87-3.el9_6.1
- Resolves: RHEL-91765
  tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)
- Resolves: RHEL-71981
  tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)

* Tue Apr 08 2025 Adam Krajcik <akrajcik@redhat.com> - 1:9.0.87-3
- Resolves: RHEL-82945
  tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT (CVE-2025-24813)
- Resolves: RHEL-71723
  tomcat: RCE due to TOCTOU issue in JSP compilation (CVE-2024-50379)

* Thu Aug 08 2024 Adam Krajcik <akrajcik@redhat.com> - 1:9.0.87-2
- Resolves: RHEL-46163
  tomcat: Improper Handling of Exceptional Conditions (CVE-2024-34750)
- Resolves: RHEL-18245 - OpenJDK 21 support for RHEL Tomcat

* Fri May 03 2024 Sokratis Zappis <szappis@redhat.com> - 1:9.0.87-1
- Resolves: RHEL-35812 - Rebase tomcat to version 9.0.87
- Resolves: RHEL-29257
  tomcat: Apache Tomcat: WebSocket DoS with incomplete closing handshake (CVE-2024-23672)
- Resolves: RHEL-29252
  tomcat: : Apache Tomcat: HTTP/2 header handling DoS (CVE-2024-24549)
- Resolves: RHEL-53001 - Amend tomcat's changelog
  (CVE-2023-46589, CVE-2023-45648, CVE-2023-42795, CVE-2023-42794, CVE-2023-44487, CVE-2023-41080)

* Thu Jan 18 2024 Hui Wang <huwang@redhat.com> - 1:9.0.62-39
- Resolves: RHEL-17605
  tomcat: HTTP request smuggling via malformed trailer headers (CVE-2023-46589)

* Thu Nov 23 2023 Hui Wang <huwang@redhat.com> - 1:9.0.62-38
- Resolves: RHEL-13908
  tomcat: incorrectly parsed http trailer headers can cause request smuggling (CVE-2023-45648)
- Resolves: RHEL-13905
  tomcat: improper cleaning of recycled objects could lead to information leak (CVE-2023-42795)
- Resolves: RHEL-12952
  tomcat: FileUpload: DoS due to accumulation of temporary files on Windows (CVE-2023-42794)
- Resolves: RHEL-12552
  tomcat: HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) (CVE-2023-44487)
- Resolves: RHEL-2388
  tomcat: Open Redirect vulnerability in FORM authentication (CVE-2023-41080)

* Fri Oct 13 2023 Hui Wang <huwang@redhat.com> - 1:9.0.62-37
- Resolves: RHEL-12551
  tomcat: HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) (CVE-2023-44487)
- Remove JDK subpackges which are unused

* Fri Aug 25 2023 Coty Sutherland <csutherl@redhat.com> - 1:9.0.62-16
- Related: #2184133 Declare file conflicts

* Fri Aug 25 2023 Coty Sutherland <csutherl@redhat.com> - 1:9.0.62-15
- Resolves: #2184133 Fix bug in Obsoletes

* Tue Aug 01 2023 Hui Wang <huwang@redhat.com> - 1:9.0.62-14
- Resolves: #2210632 CVE-2023-28709 tomcat