{
  "cves": [
    "CVE-2024-52316",
    "CVE-2024-54677",
    "CVE-2025-24813"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "MODERATE"
  },
  "description": "[1:10.1.36-1]\n- Rebase tomcat to 10.1.36\n- Resolves: RHEL-82925\n  tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT (CVE-2025-24813)\n- Resolves: RHEL-87272\n  tomcat: DoS in examples web application (CVE-2024-54677)\n- Resolves: RHEL-87273\n  tomcat: Authentication bypass when using Jakarta Authentication API (CVE-2024-52316)\n- Resolves: RHEL-85343 - NoClassDefFoundError when using migration tool",
  "id": "ELSA-2025-7497",
  "ovalId": "oval:com.oracle.elsa:def:20257497",
  "source": "oracle_linux",
  "title": "ELSA-2025-7497:  tomcat security update (MODERATE)",
  "url": "https://linux.oracle.com/errata/ELSA-2025-7497.html"
}