Impact
A Time‑of‑Check Time‑of‑Use race condition occurs in Apache Tomcat during the creation of Unix Domain Sockets. The flaw permits an unauthorized local user to gain access to the socket after it has been created. The description does not claim that the attacker can execute arbitrary commands or read arbitrary data, only that the socket can be accessed by a local user who exploits the race.
Affected Systems
Apache Tomcat provided by the Apache Software Foundation is affected. The affected releases are 11.0.0‑M1 through 11.0.24, 10.1.0‑M1 through 10.1.57, and 9.0.42 through 9.0.120.
Risk and Exploitability
The CVSS base score of 8.1 indicates high severity for local impact. The EPSS score of <1% implies a low probability of public exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a local user with sufficient file‑system permissions to perform the TOCTOU race, enabling that user to access the Unix Domain Socket, which could allow local privilege misuse within the scope of Tomcat’s configuration.
OpenCVE Enrichment