Skip to main content

Apache Releases Security Advisory for Apache Tomcat

Report a cyber attack: call 0300 303 5222 or email [email protected]

Threat details

Introduction

The Apache Software Foundation has released a security advisory to address a vulnerability in Apache Tomcat. An remote attacker could exploit this vulnerability to execute arbitrary code.


Remediation advice

The Apache Software Foundation has released updates to address this vulnerability in all supported products. Affected organisations are encouraged to apply the following updates.


Remediation steps

Type Step
Patch

Apache Tomcat 10 users update to the following version.


https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.0.2
Patch

Apache Tomcat 9 users update to the following version.


https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.43
Patch

Apache Tomcat 8 users update to the following version.


https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.63
Patch

Apache Tomcat 7 users update to the following version.


https://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.108

Last edited: 4 March 2021 12:32 pm