Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be auth
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
30일 내 악용 확률 예측
실측 악용 기록 없음
계획된 패치 주기 내 조치(60일 이내)
CVSS 벡터 · 메트릭
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N약점 (CWE)
- CWE-287
부적절한 인증 — 인증 절차가 미흡해 신원 위장이 가능.
상세 설명
Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.
영향받는 제품·버전
- apache tomcat7.0.0 - 7.0.109other
- apache tomcat8.5.0 - 9.0.121other
- apache tomcat10.1.0 - 10.1.58other
- apache tomcat11.0.0 - 11.0.25other
영향받는 구성 (CPE) 1
- apache tomcat≥ 7.0.0 ≤ 7.0.109cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
참고 자료 2
- https://lists.apache.org/thread/8robqo76q0osxgw0b5lcwgz0hcf9h4zcVendor AdvisoryMailing List
- http://www.openwall.com/lists/oss-security/2026/08/26/8Third Party AdvisoryMailing List
링크 내용 불러오는 중…