First published: Sat Jan 18 2025(Updated: )
Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception during the authentication process without explicitly setting an HTTP status to indicate failure, the authentication may not fail, allowing the user to bypass the authentication process. There are no known Jakarta Authentication components that behave in this way. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M26, from 10.1.0-M1 through 10.1.30, from 9.0.0-M1 through 9.0.95. Users are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fix the issue.
Affected Software | Affected Version | How to fix |
---|---|---|
F5 Traffix Systems Signaling Delivery Controller | =5.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of F5-K000149333 is considered to be high due to potential unauthorized access through improper error handling.
To fix F5-K000149333, ensure that your custom Jakarta Authentication ServerAuthContext component explicitly sets an HTTP status to indicate authentication failures.
F5-K000149333 affects the F5 Traffix Systems Signaling Delivery Controller version 5.2.0.
F5-K000149333 is an Unchecked Error Condition vulnerability that can allow attackers to exploit failed authentication attempts.
A workaround for F5-K000149333 includes reviewing your authentication mechanism to ensure exceptions correctly set HTTP error statuses.