[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2025-24813":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T14:55:33.319Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":223,"aliases":267,"duplicate_of":9,"upstream":270,"downstream":271,"duplicates":316,"related":317,"reserved_at":9,"published_at":329,"modified_at":330,"state":331,"summary":332,"references_raw":340,"kevs":416,"epss":427,"epss_history":430,"metrics":625,"affected":639},"CVE-2025-24813","Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1 through 9.0.98.\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions \nmay also be affected.\n\n\nIf all of the following were true, a malicious user was able to view       security sensitive files and/or inject content into those files:\n- writes enabled for the default servlet (disabled by default)\n- support for partial PUT (enabled by default)\n- a target URL for security sensitive uploads that was a sub-directory of a target URL for public uploads\n- attacker knowledge of the names of security sensitive files being uploaded\n- the security sensitive files also being uploaded via partial PUT\n\nIf all of the following were true, a malicious user was able to       perform remote code execution:\n- writes enabled for the default servlet (disabled by default)\n- support for partial PUT (enabled by default)\n- application was using Tomcat's file based session persistence with the default storage location\n- application included a library that may be leveraged in a deserialization attack\n\nUsers are recommended to upgrade to version 11.0.3, 10.1.35 or 9.0.99, which fixes the issue.",null,[11,205,211],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":9,"capec":18},"CWE-706","Use of Incorrectly-Resolved Name or Reference","The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.","weakness","Incomplete","Class",[19,109,166,170],{"id":20,"name":21,"techniques":22},"CAPEC-159","Redirect Access to Libraries",[23],{"id":24,"name":25,"tactics":26,"countermeasures":42},"T1574.008","Path Interception by Search Order Hijacking",[27,30,33,36,39],{"id":28,"name":29},"TA0110","Persistence",{"id":31,"name":32},"TA0111","Privilege Escalation",{"id":34,"name":35},"TA0030","Defense Evasion",{"id":37,"name":38},"TA0005","Stealth",{"id":40,"name":41},"TA0104","Execution",[43,48,52,56,60,65,70,75,80,85,89,93,97,101,105],{"id":44,"name":45,"tactic":46},"D3-FA","File Analysis",{"name":47},"Detect",{"id":49,"name":50,"tactic":51},"D3-FIM","File Integrity Monitoring",{"name":47},{"id":53,"name":54,"tactic":55},"D3-DA","Dynamic Analysis",{"name":47},{"id":57,"name":58,"tactic":59},"D3-EFA","Emulated File Analysis",{"name":47},{"id":61,"name":62,"tactic":63},"D3-FEV","File Eviction",{"name":64},"Evict",{"id":66,"name":67,"tactic":68},"D3-DF","Decoy File",{"name":69},"Deceive",{"id":71,"name":72,"tactic":73},"D3-FE","File Encryption",{"name":74},"Harden",{"id":76,"name":77,"tactic":78},"D3-RF","Restore File",{"name":79},"Restore",{"id":81,"name":82,"tactic":83},"D3-CF","Content Filtering",{"name":84},"Isolate",{"id":86,"name":87,"tactic":88},"D3-LFP","Local File Permissions",{"name":84},{"id":90,"name":91,"tactic":92},"D3-RFAM","Remote File Access Mediation",{"name":84},{"id":94,"name":95,"tactic":96},"D3-CQ","Content Quarantine",{"name":84},{"id":98,"name":99,"tactic":100},"D3-CM","Content Modification",{"name":84},{"id":102,"name":103,"tactic":104},"D3-EAL","Executable Allowlisting",{"name":84},{"id":106,"name":107,"tactic":108},"D3-EDL","Executable Denylisting",{"name":84},{"id":110,"name":111,"techniques":112},"CAPEC-177","Create files with the same name as files protected with a higher classification",[113],{"id":114,"name":115,"tactics":116,"countermeasures":119},"T1036","Masquerading",[117,118],{"id":34,"name":35},{"id":37,"name":38},[120,124,126,128,130,132,136,140,142,144,146,148,152,154,156,158,160,162,164],{"id":121,"name":122,"tactic":123},"D3-SCA","System Call Analysis",{"name":47},{"id":44,"name":45,"tactic":125},{"name":47},{"id":49,"name":50,"tactic":127},{"name":47},{"id":53,"name":54,"tactic":129},{"name":47},{"id":57,"name":58,"tactic":131},{"name":47},{"id":133,"name":134,"tactic":135},"D3-SFA","System File Analysis",{"name":47},{"id":137,"name":138,"tactic":139},"D3-SJA","Scheduled Job Analysis",{"name":47},{"id":61,"name":62,"tactic":141},{"name":64},{"id":66,"name":67,"tactic":143},{"name":69},{"id":71,"name":72,"tactic":145},{"name":74},{"id":76,"name":77,"tactic":147},{"name":79},{"id":149,"name":150,"tactic":151},"D3-SCF","System Call Filtering",{"name":84},{"id":81,"name":82,"tactic":153},{"name":84},{"id":86,"name":87,"tactic":155},{"name":84},{"id":90,"name":91,"tactic":157},{"name":84},{"id":94,"name":95,"tactic":159},{"name":84},{"id":98,"name":99,"tactic":161},{"name":84},{"id":102,"name":103,"tactic":163},{"name":84},{"id":106,"name":107,"tactic":165},{"name":84},{"id":167,"name":168,"techniques":169},"CAPEC-48","Passing Local Filenames to Functions That Expect a URL",[],{"id":171,"name":172,"techniques":173},"CAPEC-641","DLL Side-Loading",[174],{"id":175,"name":172,"tactics":176,"countermeasures":182},"T1574.002",[177,178,179,180,181],{"id":28,"name":29},{"id":31,"name":32},{"id":34,"name":35},{"id":37,"name":38},{"id":40,"name":41},[183,185,187,189,191,193,195,197,199,201,203],{"id":44,"name":45,"tactic":184},{"name":47},{"id":49,"name":50,"tactic":186},{"name":47},{"id":61,"name":62,"tactic":188},{"name":64},{"id":66,"name":67,"tactic":190},{"name":69},{"id":71,"name":72,"tactic":192},{"name":74},{"id":76,"name":77,"tactic":194},{"name":79},{"id":81,"name":82,"tactic":196},{"name":84},{"id":86,"name":87,"tactic":198},{"name":84},{"id":90,"name":91,"tactic":200},{"name":84},{"id":94,"name":95,"tactic":202},{"name":84},{"id":98,"name":99,"tactic":204},{"name":84},{"_key":206,"id":206,"name":207,"description":208,"type":15,"status":16,"abstraction":209,"likelihood_of_exploit":9,"capec":210},"CWE-44","Path Equivalence: 'file.name' (Internal Dot)","The product accepts path input in the form of internal dot ('file.ordir') without appropriate validation, which can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or access arbitrary files.","Variant",[],{"_key":212,"id":212,"name":213,"description":214,"type":15,"status":215,"abstraction":216,"likelihood_of_exploit":217,"capec":218},"CWE-502","Deserialization of Untrusted Data","The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.","Draft","Base","Medium",[219],{"id":220,"name":221,"techniques":222},"CAPEC-586","Object Injection",[],[224,233,245],{"_key":225,"name":226,"source":227,"url":228,"maturity":229,"reliability_score":230,"verified":231,"type":9,"platforms":232,"requires_auth":9,"exploitdb":9,"metasploit":9},"GITHUB_ABSHOLI7LY_POC-CVE-2025-24813","Poc Cve 2025 24813","github","https://github.com/absholi7ly/POC-CVE-2025-24813/blob/main/README.md","poc",0.3,false,[],{"_key":234,"name":235,"source":236,"url":237,"maturity":229,"reliability_score":238,"verified":231,"type":9,"platforms":239,"requires_auth":9,"exploitdb":241,"metasploit":9},"52134","Apache Tomcat 11.0.3 - Remote Code Execution","exploit-database","https://www.exploit-db.com/exploits/52134",0.5,[240],"multiple",{"verified":231,"type":242,"platform":240,"file":243,"codes":244},"webapps","exploits/multiple/webapps/52134.txt",[7],{"_key":246,"name":247,"source":248,"url":249,"maturity":250,"reliability_score":251,"verified":252,"type":253,"platforms":254,"requires_auth":231,"exploitdb":9,"metasploit":255},"MSF_EXPLOIT_MULTI_HTTP_TOMCAT_PARTIAL_PUT_DESERIALIZATION","Tomcat Partial PUT Java Deserialization","metasploit","https://github.com/rapid7/metasploit-framework/blob/master/modules/exploit/multi/http/tomcat_partial_put_deserialization.rb","weaponized",1,true,"remote",[],{"fullname":256,"rank":257,"rank_name":258,"post_auth":231,"check":252,"notes":259},"exploit/multi/http/tomcat_partial_put_deserialization",600,"excellent",{"Stability":260,"SideEffects":262,"Reliability":265},[261],"crash-safe",[263,264],"ioc-in-logs","artifacts-on-disk",[266],"repeatable-session",[268,269],"GHSA-83qj-6fr2-vhqg","BIT-tomcat-2025-24813",[],[272,274,276,278,280,282,284,286,288,290,292,294,296,298,300,302,304,306,308,310,312,314],{"_key":273},"SUSE-SU-2025:1024-1",{"_key":275},"SUSE-SU-2025:0954-1",{"_key":277},"SUSE-SU-2025:1126-1",{"_key":279},"OPENSUSE-SU-2025:14896-1",{"_key":281},"OPENSUSE-SU-2025:14897-1",{"_key":283},"DLA-4108-1",{"_key":285},"DSA-5893-1",{"_key":287},"SUSE-SU-2026:1058-1",{"_key":289},"UBUNTU-CVE-2025-24813",{"_key":291},"MGASA-2025-0105",{"_key":293},"USN-7525-1",{"_key":295},"USN-7525-2",{"_key":297},"DEBIAN-CVE-2025-24813",{"_key":299},"RHSA-2025:3454",{"_key":301},"RHSA-2025:3608",{"_key":303},"RHSA-2025:3645",{"_key":305},"RHSA-2025:3646",{"_key":307},"RHSA-2025:3647",{"_key":309},"RHSA-2025:3683",{"_key":311},"RHSA-2025:3684",{"_key":313},"RHSA-2025:7494",{"_key":315},"RHSA-2025:7497",[],[318,319,320,321,322,323,324,325,327],{"_key":273},{"_key":275},{"_key":277},{"_key":279},{"_key":281},{"_key":291},{"_key":287},{"_key":326},"CGA-3GJ2-76VF-63RM",{"_key":328},"CGA-XVPQ-3FMC-Q2JR","2025-03-10T16:44:03.715Z","2025-10-29T11:49:44.413Z","Analyzed",{"cisa_kev":252,"cisa_ransomware":231,"cisa_vendor":333,"epss_severity":334,"epss_score":335,"severity":334,"severity_score":336,"severity_version":337,"severity_source":338,"severity_vector":339,"severity_status":331},"Apache","critical",0.9413,10,"v3.1","cve.org","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",[341,349,355,360,364,368,372,376,380,384,390,395,399,403,407,412],{"url":342,"sources":343,"tags":346},"https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq",[338,344,345],"nvd","osv_maven",[347,348],"Vendor Advisory","WEB",{"url":350,"sources":351,"tags":352},"http://www.openwall.com/lists/oss-security/2025/03/10/5",[338,344,345],[353,354,348],"Mailing List","Third Party Advisory",{"url":356,"sources":357,"tags":358},"https://www.vicarius.io/vsociety/posts/cve-2025-24813-detect-apache-tomcat-rce",[338,344,345],[359,348],"Issue Tracking",{"url":361,"sources":362,"tags":363},"https://www.vicarius.io/vsociety/posts/cve-2025-24813-mitigate-apache-tomcat-rce",[338,344,345],[359,348],{"url":365,"sources":366,"tags":367},"https://security.netapp.com/advisory/ntap-20250321-0001/",[338,344],[354],{"url":369,"sources":370,"tags":371},"https://lists.debian.org/debian-lts-announce/2025/04/msg00003.html",[338,344,345],[353,354,348],{"url":373,"sources":374,"tags":375},"https://www.vicarius.io/vsociety/posts/cve-2025-24813-tomcat-detect-vulnerability",[338,344,345],[359,348],{"url":377,"sources":378,"tags":379},"https://www.vicarius.io/vsociety/posts/cve-2025-24813-tomcat-mitigation-vulnerability",[338,344,345],[359,348],{"url":228,"sources":381,"tags":382},[338,344,345],[383,348],"Exploit",{"url":385,"sources":386,"tags":387},"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24813",[338,344,345],[388,354,389,348],"Government Resource","US Government Resource",{"url":391,"sources":392,"tags":393},"https://nvd.nist.gov/vuln/detail/CVE-2025-24813",[345],[394],"Advisory",{"url":396,"sources":397,"tags":398},"https://github.com/apache/tomcat/commit/0a668e0c27f2b7ca0cc7c6eea32253b9b5ecb29c",[345],[348],{"url":400,"sources":401,"tags":402},"https://github.com/apache/tomcat/commit/eb61aade8f8daccaecabf07d428b877975622f72",[345],[348],{"url":404,"sources":405,"tags":406},"https://github.com/apache/tomcat/commit/f6c01d6577cf9a1e06792be47e623d36acc3b5dc",[345],[348],{"url":408,"sources":409,"tags":410},"https://github.com/apache/tomcat",[345],[411],"PACKAGE",{"url":413,"sources":414,"tags":415},"https://security.netapp.com/advisory/ntap-20250321-0001",[345],[348],[417],{"source":418,"vendor":333,"product":419,"date_added":420,"vulnerability_name":421,"short_description":422,"required_action":423,"due_date":424,"known_ransomware_campaign_use":425,"notes":426,"exploitation_type":9},"cisa","Tomcat","2025-04-01","Apache Tomcat Path Equivalence Vulnerability","Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request.","Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","2025-04-22","Unknown","This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq ; https://nvd.nist.gov/vuln/detail/CVE-2025-24813",{"date":428,"score":335,"percentile":429},"2026-06-04",0.99917,[431,435,437,439,441,443,445,447,449,452,454,456,458,460,462,466,469,472,476,478,480,482,484,486,488,490,492,494,497,499,501,503,505,507,510,512,514,516,518,520,522,524,526,528,530,533,535,537,539,541,543,545,547,549,553,555,557,559,561,563,565,567,569,571,573,575,577,579,581,583,585,587,589,591,593,595,597,599,601,603,605,607,609,611,613,615,617,619,621,623],{"date":432,"score":433,"percentile":434},"2025-11-04",0.94183,0.99911,{"date":436,"score":433,"percentile":434},"2025-11-05",{"date":438,"score":433,"percentile":434},"2025-11-06",{"date":440,"score":433,"percentile":434},"2025-11-07",{"date":442,"score":433,"percentile":434},"2025-11-08",{"date":444,"score":433,"percentile":434},"2025-11-09",{"date":446,"score":433,"percentile":434},"2025-11-10",{"date":448,"score":433,"percentile":434},"2025-11-11",{"date":450,"score":433,"percentile":451},"2025-11-12",0.99912,{"date":453,"score":433,"percentile":451},"2025-11-13",{"date":455,"score":433,"percentile":451},"2025-11-14",{"date":457,"score":433,"percentile":451},"2025-11-15",{"date":459,"score":433,"percentile":451},"2025-11-16",{"date":461,"score":433,"percentile":451},"2025-11-17",{"date":463,"score":464,"percentile":465},"2025-11-18",0.92831,0.99826,{"date":467,"score":464,"percentile":468},"2025-11-19",0.99825,{"date":470,"score":464,"percentile":471},"2025-11-20",0.99824,{"date":473,"score":474,"percentile":475},"2025-11-21",0.94228,0.9992,{"date":477,"score":474,"percentile":475},"2025-11-22",{"date":479,"score":474,"percentile":475},"2025-11-23",{"date":481,"score":433,"percentile":451},"2025-11-24",{"date":483,"score":433,"percentile":451},"2025-11-25",{"date":485,"score":433,"percentile":451},"2025-11-26",{"date":487,"score":433,"percentile":451},"2025-11-27",{"date":489,"score":433,"percentile":451},"2025-11-28",{"date":491,"score":433,"percentile":451},"2025-11-29",{"date":493,"score":433,"percentile":451},"2025-11-30",{"date":495,"score":433,"percentile":496},"2025-12-01",0.99915,{"date":498,"score":433,"percentile":496},"2025-12-02",{"date":500,"score":433,"percentile":496},"2025-12-03",{"date":502,"score":433,"percentile":451},"2025-12-04",{"date":504,"score":433,"percentile":451},"2025-12-05",{"date":506,"score":433,"percentile":451},"2025-12-06",{"date":508,"score":433,"percentile":509},"2025-12-07",0.99913,{"date":511,"score":433,"percentile":451},"2025-12-08",{"date":513,"score":433,"percentile":509},"2025-12-09",{"date":515,"score":433,"percentile":509},"2025-12-10",{"date":517,"score":433,"percentile":509},"2025-12-11",{"date":519,"score":433,"percentile":509},"2025-12-12",{"date":521,"score":433,"percentile":509},"2025-12-13",{"date":523,"score":433,"percentile":509},"2025-12-14",{"date":525,"score":433,"percentile":509},"2025-12-15",{"date":527,"score":433,"percentile":509},"2025-12-16",{"date":529,"score":433,"percentile":509},"2025-12-17",{"date":531,"score":433,"percentile":532},"2025-12-18",0.99914,{"date":534,"score":433,"percentile":532},"2025-12-19",{"date":536,"score":433,"percentile":532},"2025-12-20",{"date":538,"score":433,"percentile":496},"2025-12-21",{"date":540,"score":433,"percentile":496},"2025-12-22",{"date":542,"score":433,"percentile":496},"2025-12-23",{"date":544,"score":433,"percentile":509},"2025-12-24",{"date":546,"score":433,"percentile":509},"2025-12-25",{"date":548,"score":433,"percentile":509},"2025-12-26",{"date":550,"score":551,"percentile":552},"2025-12-27",0.94111,0.99904,{"date":554,"score":433,"percentile":509},"2025-12-28",{"date":556,"score":433,"percentile":509},"2025-12-29",{"date":558,"score":433,"percentile":509},"2025-12-30",{"date":560,"score":433,"percentile":509},"2025-12-31",{"date":562,"score":433,"percentile":496},"2026-01-01",{"date":564,"score":433,"percentile":496},"2026-01-02",{"date":566,"score":433,"percentile":496},"2026-01-03",{"date":568,"score":433,"percentile":509},"2026-01-04",{"date":570,"score":433,"percentile":509},"2026-01-05",{"date":572,"score":433,"percentile":509},"2026-01-06",{"date":574,"score":433,"percentile":532},"2026-01-07",{"date":576,"score":433,"percentile":532},"2026-01-08",{"date":578,"score":433,"percentile":532},"2026-01-09",{"date":580,"score":433,"percentile":532},"2026-01-10",{"date":582,"score":433,"percentile":532},"2026-01-11",{"date":584,"score":433,"percentile":532},"2026-01-12",{"date":586,"score":433,"percentile":532},"2026-01-13",{"date":588,"score":433,"percentile":496},"2026-01-14",{"date":590,"score":433,"percentile":496},"2026-01-15",{"date":592,"score":433,"percentile":509},"2026-01-16",{"date":594,"score":433,"percentile":509},"2026-01-17",{"date":596,"score":433,"percentile":509},"2026-01-18",{"date":598,"score":433,"percentile":451},"2026-01-19",{"date":600,"score":433,"percentile":451},"2026-01-20",{"date":602,"score":433,"percentile":451},"2026-01-21",{"date":604,"score":433,"percentile":451},"2026-01-22",{"date":606,"score":433,"percentile":451},"2026-01-23",{"date":608,"score":433,"percentile":451},"2026-01-24",{"date":610,"score":433,"percentile":509},"2026-01-25",{"date":612,"score":433,"percentile":509},"2026-01-26",{"date":614,"score":433,"percentile":509},"2026-01-27",{"date":616,"score":433,"percentile":509},"2026-01-28",{"date":618,"score":433,"percentile":509},"2026-01-29",{"date":620,"score":433,"percentile":509},"2026-01-30",{"date":622,"score":433,"percentile":532},"2026-01-31",{"date":624,"score":433,"percentile":429},"2026-02-01",[626,629,633],{"source":338,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":627,"cvss_v4_0":9},{"baseScore":336,"baseSeverity":628,"vectorString":339,"impactScore":336,"exploitabilityScore":336},"CRITICAL",{"source":344,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":630,"cvss_v4_0":9},{"baseScore":631,"baseSeverity":628,"vectorString":632,"impactScore":631,"exploitabilityScore":336},9.8,"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",{"source":345,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":634,"cvss_v4_0":636},{"baseScore":631,"baseSeverity":9,"vectorString":635,"impactScore":631,"exploitabilityScore":336},"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H",{"baseScore":637,"baseSeverity":9,"vectorString":638,"impactScore":9,"exploitabilityScore":9},9.2,"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A",[640,663,768,776,792,801],{"ecosystem":9,"name":641,"vendor":642,"product":643,"cpe_part":644,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":645},"Apache Tomcat","apache software foundation","apache tomcat","a",[646,651,655,659],{"version":647,"is_range":252,"range_type":338,"version_start":648,"version_start_type":649,"version_end":650,"version_end_type":649,"fixed_in":9},">= 11.0.0-M1, \u003C= 11.0.2","11.0.0-M1","including","11.0.2",{"version":652,"is_range":252,"range_type":338,"version_start":653,"version_start_type":649,"version_end":654,"version_end_type":649,"fixed_in":9},">= 10.1.0-M1, \u003C= 10.1.34","10.1.0-M1","10.1.34",{"version":656,"is_range":252,"range_type":338,"version_start":657,"version_start_type":649,"version_end":658,"version_end_type":649,"fixed_in":9},">= 9.0.0.M1, \u003C= 9.0.98","9.0.0.M1","9.0.98",{"version":660,"is_range":252,"range_type":338,"version_start":661,"version_start_type":649,"version_end":662,"version_end_type":649,"fixed_in":9},">= 8.5.0, \u003C= 8.5.100","8.5.0","8.5.100",{"ecosystem":9,"name":419,"vendor":9,"product":419,"cpe_part":9,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":664},[665,670,674,678,680,682,684,686,688,690,692,694,696,698,700,702,704,706,708,710,712,714,716,718,720,722,724,726,728,730,732,734,736,738,740,742,744,746,748,750,752,754,756,758,760,762,764,766],{"version":666,"is_range":252,"range_type":667,"version_start":9,"version_start_type":9,"version_end":668,"version_end_type":669,"fixed_in":9},"lt9.0.99","cpe","9.0.99","excluding",{"version":671,"is_range":252,"range_type":667,"version_start":672,"version_start_type":649,"version_end":673,"version_end_type":669,"fixed_in":9},"gte10.1.1_lt10.1.35","10.1.1","10.1.35",{"version":675,"is_range":252,"range_type":667,"version_start":676,"version_start_type":649,"version_end":677,"version_end_type":669,"fixed_in":9},"gte11.0.1_lt11.0.3","11.0.1","11.0.3",{"version":679,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"10.1.0:milestone1",{"version":681,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"10.1.0:milestone10",{"version":683,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"10.1.0:milestone11",{"version":685,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"10.1.0:milestone12",{"version":687,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"10.1.0:milestone13",{"version":689,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"10.1.0:milestone14",{"version":691,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"10.1.0:milestone15",{"version":693,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"10.1.0:milestone16",{"version":695,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"10.1.0:milestone17",{"version":697,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"10.1.0:milestone18",{"version":699,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"10.1.0:milestone19",{"version":701,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"10.1.0:milestone2",{"version":703,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"10.1.0:milestone20",{"version":705,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"10.1.0:milestone3",{"version":707,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"10.1.0:milestone4",{"version":709,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"10.1.0:milestone5",{"version":711,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"10.1.0:milestone6",{"version":713,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"10.1.0:milestone7",{"version":715,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"10.1.0:milestone8",{"version":717,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"10.1.0:milestone9",{"version":719,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone1",{"version":721,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone10",{"version":723,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone11",{"version":725,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone12",{"version":727,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone13",{"version":729,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone14",{"version":731,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone15",{"version":733,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone16",{"version":735,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone17",{"version":737,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone18",{"version":739,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone19",{"version":741,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone2",{"version":743,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone20",{"version":745,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone21",{"version":747,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone22",{"version":749,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone23",{"version":751,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone24",{"version":753,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone25",{"version":755,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone3",{"version":757,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone4",{"version":759,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone5",{"version":761,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone6",{"version":763,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone7",{"version":765,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone8",{"version":767,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone9",{"ecosystem":9,"name":769,"vendor":770,"product":771,"cpe_part":772,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":773},"debian linux","debian","debian_linux","o",[774],{"version":775,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0",{"ecosystem":777,"name":778,"vendor":779,"product":780,"cpe_part":9,"purl_type":781,"purl_namespace":779,"purl_name":780,"source":9,"versions":782},"Maven","org.apache.tomcat:tomcat-catalina","org.apache.tomcat","tomcat-catalina","maven",[783,786,788,790],{"version":784,"is_range":252,"range_type":785,"version_start":648,"version_start_type":649,"version_end":677,"version_end_type":669,"fixed_in":9},"gte11_0_0_M1_lt11_0_3","ecosystem",{"version":787,"is_range":252,"range_type":785,"version_start":653,"version_start_type":649,"version_end":673,"version_end_type":669,"fixed_in":9},"gte10_1_0_M1_lt10_1_35",{"version":789,"is_range":252,"range_type":785,"version_start":657,"version_start_type":649,"version_end":668,"version_end_type":669,"fixed_in":9},"gte9_0_0_M1_lt9_0_99",{"version":791,"is_range":252,"range_type":785,"version_start":661,"version_start_type":649,"version_end":662,"version_end_type":649,"fixed_in":9},"gte8_5_0_lte8_5_100",{"ecosystem":777,"name":793,"vendor":794,"product":795,"cpe_part":9,"purl_type":781,"purl_namespace":794,"purl_name":795,"source":9,"versions":796},"org.apache.tomcat.embed:tomcat-embed-core","org.apache.tomcat.embed","tomcat-embed-core",[797,798,799,800],{"version":784,"is_range":252,"range_type":785,"version_start":648,"version_start_type":649,"version_end":677,"version_end_type":669,"fixed_in":9},{"version":787,"is_range":252,"range_type":785,"version_start":653,"version_start_type":649,"version_end":673,"version_end_type":669,"fixed_in":9},{"version":789,"is_range":252,"range_type":785,"version_start":657,"version_start_type":649,"version_end":668,"version_end_type":669,"fixed_in":9},{"version":791,"is_range":252,"range_type":785,"version_start":661,"version_start_type":649,"version_end":662,"version_end_type":649,"fixed_in":9},{"ecosystem":9,"name":802,"vendor":803,"product":804,"cpe_part":772,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":805},"bootstrap os","netapp","bootstrap_os",[806],{"version":807,"is_range":231,"range_type":667,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"na"]