Количество 18
Количество 18
CVE-2026-66422
Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole(). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.25 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.46 through 8.5.100, from 7.0.97 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
CVE-2026-66422
Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole(). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.25 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.46 through 8.5.100, from 7.0.97 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
CVE-2026-66422
Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole(). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.25 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.46 through 8.5.100, from 7.0.97 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
CVE-2026-66422
Improper Authorization vulnerability in Apache Tomcat cause by securit ...
ROS-20260922-80-0099
Уязвимость tomcat11
ROS-20260922-80-0098
Уязвимость tomcat10
ROS-20260922-80-0097
Уязвимость tomcat
ROS-20260922-73-0074
Уязвимость tomcat11
ROS-20260922-73-0073
Уязвимость tomcat10
ROS-20260922-73-0072
Уязвимость tomcat
GHSA-w3xg-786f-g788
Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole(). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.25 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.46 through 8.5.100, from 7.0.97 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
SUSE-SU-2026:4203-1
Security update for tomcat
SUSE-SU-2026:4126-1
Security update for tomcat
SUSE-SU-2026:4119-1
Security update for tomcat10
SUSE-SU-2026:4114-1
Security update for tomcat11
openSUSE-SU-2026:21823-1
Security update for tomcat
openSUSE-SU-2026:21811-1
Security update for tomcat11
openSUSE-SU-2026:21810-1
Security update for tomcat10
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-66422 Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole(). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.25 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.46 through 8.5.100, from 7.0.97 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue. | CVSS3: 8.1 | 1% Низкий | 30 дней назад | |
CVE-2026-66422 Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole(). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.25 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.46 through 8.5.100, from 7.0.97 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue. | CVSS3: 2.7 | 1% Низкий | 30 дней назад | |
CVE-2026-66422 Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole(). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.25 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.46 through 8.5.100, from 7.0.97 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue. | CVSS3: 8.1 | 1% Низкий | 30 дней назад | |
CVE-2026-66422 Improper Authorization vulnerability in Apache Tomcat cause by securit ... | CVSS3: 8.1 | 1% Низкий | 30 дней назад | |
ROS-20260922-80-0099 Уязвимость tomcat11 | CVSS3: 8.1 | 1% Низкий | 3 дня назад | |
ROS-20260922-80-0098 Уязвимость tomcat10 | CVSS3: 8.1 | 1% Низкий | 3 дня назад | |
ROS-20260922-80-0097 Уязвимость tomcat | CVSS3: 8.1 | 1% Низкий | 3 дня назад | |
ROS-20260922-73-0074 Уязвимость tomcat11 | CVSS3: 8.1 | 1% Низкий | 3 дня назад | |
ROS-20260922-73-0073 Уязвимость tomcat10 | CVSS3: 8.1 | 1% Низкий | 3 дня назад | |
ROS-20260922-73-0072 Уязвимость tomcat | CVSS3: 8.1 | 1% Низкий | 3 дня назад | |
GHSA-w3xg-786f-g788 Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole(). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.25 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.46 through 8.5.100, from 7.0.97 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue. | CVSS3: 8.1 | 1% Низкий | 30 дней назад | |
SUSE-SU-2026:4203-1 Security update for tomcat | 8 дней назад | |||
SUSE-SU-2026:4126-1 Security update for tomcat | 13 дней назад | |||
SUSE-SU-2026:4119-1 Security update for tomcat10 | 14 дней назад | |||
SUSE-SU-2026:4114-1 Security update for tomcat11 | 15 дней назад | |||
openSUSE-SU-2026:21823-1 Security update for tomcat | 15 дней назад | |||
openSUSE-SU-2026:21811-1 Security update for tomcat11 | 16 дней назад | |||
openSUSE-SU-2026:21810-1 Security update for tomcat10 | 16 дней назад |
Уязвимостей на страницу