Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed af
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
30일 내 악용 확률 예측
실측 악용 기록 없음
계획된 패치 주기 내 조치(60일 이내)
CVSS 벡터 · 메트릭
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N약점 (CWE)
상세 설명
Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been established under that authenticated HTTP session, the WebSokcet session would not be closed as required by the Jakarta WebSocket specification when the HTTP session ended.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.
영향받는 제품·버전
- apache tomcat7.0.43 - 7.0.109other
- apache tomcat8.5.0 - 9.0.121other
- apache tomcat10.1.0 - 10.1.58other
- apache tomcat11.0.0 - 11.0.25other
영향받는 구성 (CPE) 1
- apache tomcat≥ 7.0.43 ≤ 7.0.109cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
참고 자료 2
- https://lists.apache.org/thread/3j15vztszpyqss253mjq5v1kp7s6hooqVendor AdvisoryMailing List
- http://www.openwall.com/lists/oss-security/2026/08/26/10Third Party AdvisoryMailing List
링크 내용 불러오는 중…