Impact
The vulnerability arises from an always‑incorrect control flow in Apache Tomcat that causes the logged effective web.xml to omit special roles and empty authorization constraints. Based on the description, the omission of these configuration elements in the logs could enable an attacker who can read the Tomcat logs to gain insight into the application’s access control policies, a potential information disclosure.
Affected Systems
Apache Tomcat versions 8.5.0 through 8.5.100, 9.0.0.M1 through 9.0.118, 10.1.0-M1 through 10.1.55, and 11.0.0-M1 through 11.0.22 are vulnerable. Unsupported or end‑of‑support releases may also be affected.
Risk and Exploitability
CVSS score 9.1 denotes high severity. EPSS score is below 1 percent, indicating low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local or remote read access to Tomcat log files. Based on the description, the attacker would need to obtain the logs to gain the disclosed information, so privilege escalation or compromised user accounts may be required to read the logs. The potential impact for confidentiality is significant if logs are exposed. The risk remains high due to the severity score and the possibility of attackers leveraging misconfigured log permissions.
OpenCVE Enrichment
Ubuntu USN