PT-2026-81876 · Apache · Apache Tomcat
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Tomcat versions 11.0.0-M1 through 11.0.24
Apache Tomcat versions 10.1.0-M1 through 10.1.57
Apache Tomcat versions 9.0.0.M1 through 9.0.120
Apache Tomcat versions 8.5.0 through 8.5.100
Apache Tomcat versions 7.0.0 through 7.0.109
Description
Improper access control and incorrect authorization allow an unauthenticated attacker to bypass security constraints. This occurs when a security constraint for a longer path is processed before a more restrictive constraint for a shorter sub-path, leading the system to evaluate constraints incorrectly and grant access to protected resources.
Recommendations
Upgrade Apache Tomcat versions 11.0.0-M1 through 11.0.24 to version 11.0.25.
Upgrade Apache Tomcat versions 10.1.0-M1 through 10.1.57 to version 10.1.58.
Upgrade Apache Tomcat versions 9.0.0.M1 through 9.0.120 to version 9.0.121.
At the moment, there is no information about a newer version that contains a fix for Apache Tomcat versions 8.5.0 through 8.5.100.
At the moment, there is no information about a newer version that contains a fix for Apache Tomcat versions 7.0.0 through 7.0.109.
Exploit
Fix
DoS
Improper Access Control
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Tomcat