Apache Tomcat
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*, +1 more
- >= 11.0.0-M1, <= 11.0.21
- >= 10.1.0-M1, <= 10.1.54
- >= 9.0.0.M1, <= 9.0.117
- < 7.0.0
A vulnerability allowing authentication bypass in digest authentication has been identified in Apache Tomcat. This issue affects versions 11.0.0-M1 prior to 11.0.21, 10.1.0-M1 prior to 10.1.54, 9.0.0-M1 prior to 9.0.117, and 8.5.0 prior to 8.5.100. Older, unsupported versions may also be affected. The vulnerability arises because, when DIGEST authentication is enabled, any user not recognized by the configured Realm can be authenticated by presenting the password 'null'.
Exploitation of this vulnerability allows any unknown user to be authenticated when DIGEST authentication is used, potentially leading to unauthorized access.
Users are advised to upgrade to Apache Tomcat 11.0.22, 10.1.55, or 9.0.118.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.