Apache Tomcat
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*, +1 more
- >= 11.0.0-M1, <= 11.0.21
- >= 10.1.0-M1, <= 10.1.54
- >= 9.0.0.M1, <= 9.0.117
- >= 8.5.0, <= 8.5.100
- >= 7.0.0, <= 7.0.109
A vulnerability has been identified in Apache Tomcat that allows improper authorization when multiple method constraints are defined for the same extension pattern. This issue affects Apache Tomcat versions 11.0.0-M1 prior to 11.0.21, 10.1.0-M1 prior to 10.1.54, 9.0.0-M1 prior to 9.0.117, 8.5.0 prior to 8.5.100, and 7.0.0 prior to 7.0.109. In the affected versions, only the first method constraint is applied, potentially leading to unauthorized access.
This vulnerability can result in security constraints not being correctly enforced, allowing unauthorized users to access resources or methods they should not be able to.
Users are advised to upgrade to Apache Tomcat versions 11.0.22, 10.1.55, or 9.0.118.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.