Apache Tomcat
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*, +1 more
- >= 11.0.0-M1, <= 11.0.21
- >= 10.1.0-M1, <= 10.1.54
- >= 9.0.0.M1, <= 9.0.117
- < 7.0
A vulnerability exists in Apache Tomcat due to an observable timing discrepancy when comparing AJP secrets. This flaw allows an attacker on the local network to perform a timing attack to deduce the AJP secret. The vulnerability is present in Apache Tomcat versions 11.0.0-M1 prior to 11.0.21, 10.1.0-M1 prior to 10.1.54, 9.0.0-M1 prior to 9.0.117, 8.5.0 prior to 8.5.100, and 7.0.0 prior to 7.0.109. Older unsupported versions may also be affected.
Exploitation of this vulnerability could lead to a timing attack, allowing an attacker to infer the AJP secret.
Users are advised to upgrade to Apache Tomcat 11.0.22, 10.1.55, or 9.0.118.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.