{"cves":["CVE-2024-50379","CVE-2025-24813"],"cvss":0.0,"database_specific":{"severity":"MODERATE"},"description":"[1:9.0.87-1.el8_10.3]\n- Resolves: RHEL-82934\n  tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT (CVE-2025-24813)\n- Resolves: RHEL-71708\n  tomcat: RCE due to TOCTOU issue in JSP compilation (CVE-2024-50379)","id":"ELSA-2025-3683","ovalId":"oval:com.oracle.elsa:def:20253683","source":"oracle_linux","title":"ELSA-2025-3683:  tomcat security update (MODERATE)","url":"https://linux.oracle.com/errata/ELSA-2025-3683.html"}