Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-43514

Опубликовано: 12 мая 2026
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Older unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.

A flaw was found in Apache Tomcat. The AJP secret was comparable in non-constant time, allowing an attacker on the local network to mount a timing attack to determine the AJP secret, which may lead to unauthorized access or other security bypasses.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Certificate System 10redhat-pki:10/jssFix deferred
Red Hat Enterprise Linux 10jssFix deferred
Red Hat Enterprise Linux 10mod_proxy_clusterFix deferred
Red Hat Enterprise Linux 8tomcatFix deferred
Red Hat Enterprise Linux 9jssFix deferred
Red Hat Enterprise Linux 9mod_proxy_clusterFix deferred
Red Hat Fuse 7tomcat-coyoteOut of support scope
Red Hat JBoss Core Servicesjbcs-httpd24-mod_cluster-nativeFix deferred
Red Hat JBoss Core Servicesjbcs-httpd24-mod_proxy_clusterFix deferred
Red Hat JBoss Enterprise Application Platform Expansion Packtomcat-coyoteOut of support scope

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-208
https://bugzilla.redhat.com/show_bug.cgi?id=2476512tomcat-coyote: Apache Tomcat: Information disclosure via AJP secret timing discrepancy

EPSS

Процентиль: 28%
0.00352
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
4 месяца назад

Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Older unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.

CVSS3: 3.7
nvd
4 месяца назад

Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Older unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.

CVSS3: 3.7
debian
4 месяца назад

Observable Timing Discrepancy vulnerabilitywhen comparing AJP secret i ...

CVSS3: 3.7
redos
3 месяца назад

Уязвимость tomcat11

CVSS3: 3.7
redos
3 месяца назад

Уязвимость tomcat10

EPSS

Процентиль: 28%
0.00352
Низкий

3.7 Low

CVSS3