Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-43515

Опубликовано: 12 мая 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 9.1

Описание

Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.

РелизСтатусПримечание
devel

not-affected

10.1.55-1ubuntu1
esm-apps/noble

released

10.1.16-1ubuntu0.1~esm4
esm-apps/resolute

released

10.1.40-1ubuntu1.26.04.1
jammy

DNE

noble

needed

questing

released

10.1.40-1ubuntu1.25.10.1
resolute

released

10.1.40-1ubuntu1.26.04.1
upstream

released

10.1.55

Показывать по

РелизСтатусПримечание
devel

not-affected

11.0.22
esm-apps/resolute

released

11.0.18-1ubuntu0.1~esm1
jammy

DNE

noble

DNE

questing

ignored

end of life, was needed
resolute

needed

upstream

released

11.0.22

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps-legacy/xenial

not-affected

see notes
esm-apps/xenial

ignored

end of ESM support, was needs-triage
esm-infra-legacy/trusty

released

6.0.39-1ubuntu0.1+esm3
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps-legacy/xenial

released

7.0.68-1ubuntu0.4+esm4
esm-apps/bionic

not-affected

see notes
esm-apps/xenial

ignored

end of ESM support, was needs-triage
esm-infra-legacy/trusty

released

7.0.52-1ubuntu0.16+esm2
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/bionic

released

8.5.39-1ubuntu1~18.04.3+esm6
esm-infra-legacy/xenial

released

8.0.32-1ubuntu1.13+esm2
esm-infra/xenial

ignored

end of ESM support, was needs-triage
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

not-affected

9.0.118-1
esm-apps/bionic

released

9.0.16-3ubuntu0.18.04.2+esm8
esm-apps/focal

released

9.0.31-1ubuntu0.9+esm3
esm-apps/jammy

released

9.0.58-1ubuntu0.2+esm4
esm-apps/noble

released

9.0.70-2ubuntu0.1+esm3
esm-apps/resolute

released

9.0.115-1ubuntu0.1
jammy

needed

noble

needed

questing

released

9.0.95-1ubuntu1.1
resolute

released

9.0.115-1ubuntu0.1

Показывать по

EPSS

Процентиль: 63%
0.01136
Низкий

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 5.4
redhat
3 месяца назад

Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.

CVSS3: 9.1
nvd
3 месяца назад

Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.

CVSS3: 9.1
debian
3 месяца назад

Improper Authorization vulnerability when multiple method constraints ...

CVSS3: 9.1
github
3 месяца назад

Apache Tomcat - Security constraints not correctly applied

CVSS3: 9.1
fstec
3 месяца назад

Уязвимость сервера приложений Apache Tomcat, связанная c недостатками процедуры авторизации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 63%
0.01136
Низкий

9.1 Critical

CVSS3