Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-43514

Опубликовано: 12 мая 2026
Источник: redhat
CVSS3: 3.7

Описание

Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Older unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.

A flaw was found in Apache Tomcat. The AJP secret was comparable in non-constant time, allowing an attacker on the local network to mount a timing attack to determine the AJP secret, which may lead to unauthorized access or other security bypasses.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Certificate System 10redhat-pki:10/jssUnder investigation
Red Hat Enterprise Linux 10jssFix deferred
Red Hat Enterprise Linux 10mod_proxy_clusterFix deferred
Red Hat Enterprise Linux 9jssFix deferred
Red Hat Enterprise Linux 9mod_proxy_clusterFix deferred
Red Hat Fuse 7tomcat-coyoteUnder investigation
Red Hat JBoss Core Servicesjbcs-httpd24-mod_cluster-nativeUnder investigation
Red Hat JBoss Core Servicesjbcs-httpd24-mod_proxy_clusterUnder investigation
Red Hat JBoss Enterprise Application Platform Expansion Packtomcat-coyoteUnder investigation
Red Hat JBoss Web Server 5jws5-mod_clusterUnder investigation

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-208
https://bugzilla.redhat.com/show_bug.cgi?id=2476512tomcat-coyote: Apache Tomcat: Information disclosure via AJP secret timing discrepancy

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
3 месяца назад

Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Older unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.

CVSS3: 3.7
nvd
3 месяца назад

Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Older unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.

CVSS3: 3.7
debian
3 месяца назад

Observable Timing Discrepancy vulnerabilitywhen comparing AJP secret i ...

CVSS3: 3.7
github
3 месяца назад

Apache Tomcat - AJP secret compared in non-constant time

CVSS3: 7.5
fstec
3 месяца назад

Уязвимость сервера приложений Apache Tomcat, связанная с раскрытием информации из-за несоответствия во времени, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

3.7 Low

CVSS3