Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limi
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
30일 내 악용 확률 예측
실측 악용 기록 없음
2주 이내 패치 — 우선 조치 대상
CVSS 벡터 · 메트릭
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N약점 (CWE)
- CWE-863
잘못된 권한 검사 — 권한 판단 로직 오류로 부적절한 접근 허용.
상세 설명
Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fixes the issue.
AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.
영향받는 제품·버전
- apache tomcat7.0.0 - 7.0.109other
- apache tomcat8.5.0 - 9.0.121other
- apache tomcat10.1.0 - 10.1.58other
- apache tomcat11.0.0 - 11.0.25other
영향받는 구성 (CPE) 1
- apache tomcat≥ 7.0.0 ≤ 7.0.109cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
참고 자료 2
- https://lists.apache.org/thread/x1y2lfsgzxwzc456f8954vbvgn03zhd7Vendor AdvisoryMailing List
- http://www.openwall.com/lists/oss-security/2026/08/26/7Third Party AdvisoryMailing List
링크 내용 불러오는 중…