Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within t
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
30일 내 악용 확률 예측
실측 악용 기록 없음
계획된 패치 주기 내 조치(60일 이내)
CVSS 벡터 · 메트릭
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H약점 (CWE)
상세 설명
Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole().
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.25 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.46 through 8.5.100, from 7.0.97 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.
영향받는 제품·버전
- apache tomcat7.0.97 - 7.0.109other
- apache tomcat8.5.46 - 9.0.121other
- apache tomcat10.1.0 - 10.1.58other
- apache tomcat11.0.0 - 11.0.25other
영향받는 구성 (CPE) 1
- apache tomcat≥ 7.0.97 ≤ 7.0.109cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
참고 자료 2
- https://lists.apache.org/thread/j5plylz1b2vhqvbkqn7k58nygxhcpk73Vendor AdvisoryMailing List
- http://www.openwall.com/lists/oss-security/2026/08/26/6Third Party AdvisoryMailing List
링크 내용 불러오는 중…