Apache Tomcat LockOutRealm Improper Case Sensitivity Handling Vulnerability

Vulnerability

A vulnerability exists in the LockOutRealm component of Apache Tomcat, where user names are treated as case-sensitive. This issue affects Apache Tomcat versions 11.0.0-M1 prior to 11.0.21, 10.1.0-M1 prior to 10.1.54, 9.0.0-M1 prior to 9.0.117, 8.5.0 prior to 8.5.100, and 7.0.0 prior to 7.0.109. Older unsupported versions may also be affected. The case sensitivity can reduce the effectiveness of the LockOutRealm in preventing brute force attacks on user passwords, particularly in realms where user names are case-insensitive.

Impact

The vulnerability can lead to decreased effectiveness of the LockOutRealm in blocking brute force password attacks, allowing for a higher risk of successful unauthorized access.

Remediation

Users should upgrade to Apache Tomcat 11.0.22 or later, 10.1.55 or later, or 9.0.118 or later.

Added: May 12, 2026, 4:19 PM
Updated: May 12, 2026, 4:19 PM

Vulnerability Rating

Custom Algorithm
spread
8.8
impact
0.6
exploitability
7.2
remediation
7.7
relevance
8.1
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.