Apache Tomcat
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*, +1 more
- >= 11.0.0-M1, <= 11.0.21
- >= 10.1.0-M1, <= 10.1.54
- >= 9.0.0.M1, <= 9.0.117
- < 7.0
A vulnerability exists in the LockOutRealm component of Apache Tomcat, where user names are treated as case-sensitive. This issue affects Apache Tomcat versions 11.0.0-M1 prior to 11.0.21, 10.1.0-M1 prior to 10.1.54, 9.0.0-M1 prior to 9.0.117, 8.5.0 prior to 8.5.100, and 7.0.0 prior to 7.0.109. Older unsupported versions may also be affected. The case sensitivity can reduce the effectiveness of the LockOutRealm in preventing brute force attacks on user passwords, particularly in realms where user names are case-insensitive.
The vulnerability can lead to decreased effectiveness of the LockOutRealm in blocking brute force password attacks, allowing for a higher risk of successful unauthorized access.
Users should upgrade to Apache Tomcat 11.0.22 or later, 10.1.55 or later, or 9.0.118 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.