REDHAT-BUG-2476512: Low severity Apache Tomcat vulnerability
Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Older unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 11.0.22 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 10.1.55 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 9.0.118
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2476512?
The severity of REDHAT-BUG-2476512 is classified as low.
What is the nature of the vulnerability in REDHAT-BUG-2476512?
REDHAT-BUG-2476512 is an Observable Timing Discrepancy vulnerability related to comparing AJP secrets in Apache Tomcat.
Which versions of Apache Tomcat are affected by REDHAT-BUG-2476512?
REDHAT-BUG-2476512 affects Apache Tomcat versions from 11.0.0-M1 through 11.0.21, 10.1.0-M1 through 10.1.54, 9.0.0.M1 through 9.0.117, 8.5.0 through 8.5.100, and 7.0.0 through 7.0.109.
Is there an available fix for REDHAT-BUG-2476512?
To resolve REDHAT-BUG-2476512, users should upgrade Apache Tomcat to a version that is not affected by this vulnerability.
What are the potential risks of not addressing REDHAT-BUG-2476512?
Failing to address REDHAT-BUG-2476512 may expose systems to timing attacks that exploit the observable discrepancies in AJP secret comparisons.