PT-2026-53742 · Apache+2 · Apache Tomcat+2
CVSS v2.0
9.4
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Tomcat versions 11.0.0-M1 through 11.0.22
Apache Tomcat versions 10.1.0-M7 through 10.1.55
Apache Tomcat versions 9.0.83 through 9.0.118
Description
An issue exists in the FFM-based TLS connector when certificate revocation lists (CRLs) are configured. The software detects an error condition during CRL processing but fails to act upon it, leading to improper error handling. A remote attacker can exploit this during TLS client-certificate authentication by presenting a certificate that should be rejected. If the CRL configuration is invalid, the system ignores the error and may accept invalid certificates, potentially resulting in authentication bypass, unauthorized access to protected endpoints, or a denial of service.
Recommendations
Upgrade Apache Tomcat versions 11.0.0-M1 through 11.0.22 to version 11.0.23.
Upgrade Apache Tomcat versions 10.1.0-M7 through 10.1.55 to version 10.1.56.
Upgrade Apache Tomcat versions 9.0.83 through 9.0.118 to version 9.0.119.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Tomcat
Confluence
Red Os