Impact
The vulnerability is a missing critical step in authentication for Apache Tomcat when the JNDIRealm component is configured to perform GSSAPI authenticated binds. This deficiency allows an attacker to authenticate to the application without providing a valid password. The flaw is classified as a credential verification weakness (CWE-304). The impact is the ability to authenticate as any user without authorization.
Affected Systems
Apache Tomcat versions that are affected include the full range of releases from 7.0.0 through 7.0.109, 8.5.0 through 8.5.100, 9.0.0.M1 through 9.0.100, 10.1.0-M1 through 10.1.36, and 11.0.0-M1 through 11.0.4. The flaw is present in all major Tomcat branches up to the specified patch releases.
Risk and Exploitability
The CVSS score of 7.3 indicates high severity, but the EPSS score is 3%, implying that the probability of exploitation is low. The flaw is not listed in the CISA KEV catalog, so no known public exploits are documented. No specific attack vector or environment requirements are stated in the CVE description beyond the need for JNDIRealm with GSSAPI, so the exploitation scenario remains unknown beyond that configuration.
OpenCVE Enrichment