Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118.
Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade tomcat-jsvcUpgrade tomcat-docs-webappUpgrade tomcat-el-3.0-apiUpgrade tomcat-webappsUpgrade tomcatUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-libUpgrade tomcat-servlet-4.0-apiUpgrade tomcat-admin-webapps | Jul 21, 2026 | Jul 21, 2026 |
| Apache Tomcat | — | Upgrade Apache Tomcat to 10.1.56Upgrade Apache Tomcat to 11.0.23Upgrade Apache Tomcat to the latest available versionUpgrade Apache Tomcat to 9.0.119 | Jun 30, 2026 | Jun 29, 2026 |
| Atlassian Jira | — | Upgrade to the latest version of Atlassian JIRA | Sep 16, 2026 | Sep 15, 2026 |
| Debian | — | Upgrade tomcat9 | Jul 1, 2026 | Jul 1, 2026 |
| Redhat_linux | — | Upgrade jws7-tomcat-selinuxUpgrade jws7-tomcat-webappsUpgrade jws7-tomcat-admin-webappsUpgrade jws7-tomcat-docs-webappUpgrade jws7-tomcat-servlet-6.0-apiNo solution existsUpgrade jws7-tomcatUpgrade jws7-tomcat-jsp-3.1-apiUpgrade jws7-tomcat-el-5.0-apiUpgrade jws7-tomcat-javadocUpgrade jws7-tomcat-lib | Jul 17, 2026 | Jun 29, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Sep 23, 2026 | Jun 29, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub