Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Ilan Toyter

#36918of 56,330
7.5Total CVSS
Vulnerabilities · 1
PT-2026-53746
7.5
2025-03-07
Apache · Apache Tomcat · CVE-2026-55957
**Name of the Vulnerable Software and Affected Versions** Apache Tomcat versions 11.0.0-M1 through 11.0.4 Apache Tomcat versions 10.1.0-M1 through 10.1.36 Apache Tomcat versions 9.0.0.M1 through 9.0.100 Apache Tomcat versions 8.5.0 through 8.5.100 Apache Tomcat versions 7.0.0 through 7.0.109 **Description** A missing critical step in the authentication process occurs when the `JNDIRealm` is configured to authenticate binds using GSSAPI (Generic Security Services Application Program Interface), a standard for security software to provide authentication services. This flaw allows attackers to authenticate successfully without providing the correct password. **Recommendations** Upgrade to version 11.0.5 Upgrade to version 10.1.37 Upgrade to version 9.0.101