Impact
The vulnerability is an authentication bypass in Tomcat's digest authenticator that allows any request with an unknown user name to be accepted as authenticated. This flaw lets an attacker perform all actions that a legitimate authenticated user can normally execute, including accessing protected resources and sensitive data. The weakness is defined by CWE-592, indicating improper handling of authentication information.
Affected Systems
Apache Tomcat versions 11.0.0-M1 through 11.0.21, 10.1.0-M1 through 10.1.54, 9.0.0.M1 through 9.0.117, 8.5.0 through 8.5.100, and all releases dated before 7.0.0 are vulnerable. Unsupported older releases are also likely affected.
Risk and Exploitability
The CVSS score is not disclosed in the public advisory, and the EPSS score is currently unavailable. The vulnerability is not listed in CISA's KEV database. Because the flaw is triggered before credential verification, it is likely exploitable over the network by any client that can reach the Tomcat instance. Attackers could masquerade as legitimate users and gain unauthorized access to protected resources.
OpenCVE Enrichment