Apache Releases Security Advisory for Tomcat

Original release date: March 2, 2021

The Apache Software Foundation has released a security advisory to address a vulnerability in multiple versions of Apache Tomcat 9.0. An attacker could exploit this vulnerability to access sensitive information.

CISA encourages users and administrators to review the Apache security advisory for CVE-2021-25122 and upgrade to the appropriate version.

This product is provided subject to this Notification and this Privacy & Use policy.