Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-68525

Опубликовано: 25 авг. 2026
Источник: redhat
CVSS3: 6.5

Описание

Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fixes the issue.

A flaw was found in Apache Tomcat. This incorrect authorization vulnerability occurs within the FORM authentication process, allowing a user to bypass security constraints. This bypass enables unauthorized access to resources via a GET request, even when those resources are intended to be restricted to POST requests only.

Отчет

This Moderate impact vulnerability in Apache Tomcat's FORM authentication process, as utilized in Red Hat JBoss Web Server, allows an attacker to bypass security constraints for POST requests. This enables unauthorized access to resources that are configured to restrict POST access while permitting GET, potentially leading to unintended data exposure or manipulation.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10tomcatUnder investigation
Red Hat Enterprise Linux 10tomcat9Under investigation
Red Hat Enterprise Linux 6tomcat6Under investigation
Red Hat Enterprise Linux 7tomcatUnder investigation
Red Hat Enterprise Linux 8pki-deps:10.6/pki-servlet-engineUnder investigation
Red Hat Enterprise Linux 8tomcatUnder investigation
Red Hat Enterprise Linux 9tomcatUnder investigation
Red Hat JBoss Web Server 5tomcatOut of support scope
Red Hat JBoss Web Server 6tomcatAffected
Red Hat JBoss Web Server 7tomcatAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-551
https://bugzilla.redhat.com/show_bug.cgi?id=2524162org.apache.tomcat/tomcat: Apache Tomcat: Unauthorized resource access via FORM authentication bypass

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
30 дней назад

Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fixes the issue.

CVSS3: 9.1
nvd
30 дней назад

Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fixes the issue.

CVSS3: 9.1
debian
30 дней назад

Incorrect Authorization vulnerability in Apache Tomcat's FORM authenti ...

CVSS3: 9.1
redos
3 дня назад

Уязвимость tomcat11

CVSS3: 9.1
redos
3 дня назад

Уязвимость tomcat10

6.5 Medium

CVSS3