{"id":"USN-8383-1","summary":"tomcat6, tomcat7 vulnerabilities","details":"It was discovered that Tomcat incorrectly handled digest\nauthentication. A remote attacker could possibly use this issue to\nbypass authentication restrictions. (CVE-2026-43512)\n\nIt was discovered that Tomcat incorrectly handled case sensitivity\nin LockOutRealm. A remote attacker could possibly use this issue to\nbypass account lockout protections and obtain sensitive information.\n(CVE-2026-43513)\n\nIt was discovered that Tomcat incorrectly handled authorization when\nmultiple method constraints defined the same HTTP method. A remote\nattacker could possibly use this issue to bypass authorization\nrestrictions. (CVE-2026-43515)","modified":"2026-06-05T11:29:17.397846203Z","published":"2026-06-04T13:15:22Z","related":["UBUNTU-CVE-2026-43512","UBUNTU-CVE-2026-43513","UBUNTU-CVE-2026-43515"],"upstream":["UBUNTU-CVE-2026-43512","UBUNTU-CVE-2026-43513","UBUNTU-CVE-2026-43515"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8383-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-43512"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-43513"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-43515"}],"affected":[{"package":{"name":"tomcat6","ecosystem":"Ubuntu:Pro:14.04:LTS","purl":"pkg:deb/ubuntu/tomcat6?arch=source&distro=esm-infra-legacy%2Ftrusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.39-1ubuntu0.1+esm3"}]}],"versions":["6.0.37-1","6.0.39-1","6.0.39-1ubuntu0.1","6.0.39-1ubuntu0.1+esm1","6.0.39-1ubuntu0.1+esm2"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro","binaries":[{"binary_name":"libservlet2.4-java","binary_version":"6.0.39-1ubuntu0.1+esm3"},{"binary_version":"6.0.39-1ubuntu0.1+esm3","binary_name":"libservlet2.5-java"},{"binary_version":"6.0.39-1ubuntu0.1+esm3","binary_name":"libtomcat6-java"},{"binary_version":"6.0.39-1ubuntu0.1+esm3","binary_name":"tomcat6"},{"binary_version":"6.0.39-1ubuntu0.1+esm3","binary_name":"tomcat6-admin"},{"binary_version":"6.0.39-1ubuntu0.1+esm3","binary_name":"tomcat6-common"},{"binary_version":"6.0.39-1ubuntu0.1+esm3","binary_name":"tomcat6-docs"},{"binary_version":"6.0.39-1ubuntu0.1+esm3","binary_name":"tomcat6-examples"},{"binary_version":"6.0.39-1ubuntu0.1+esm3","binary_name":"tomcat6-extras"},{"binary_version":"6.0.39-1ubuntu0.1+esm3","binary_name":"tomcat6-user"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8383-1.json","cves_map":{"cves":[{"id":"CVE-2026-43512","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-43513","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-43515","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"},{"type":"Ubuntu","score":"medium"}]}],"ecosystem":"Ubuntu:Pro:14.04:LTS"}}},{"package":{"name":"tomcat7","ecosystem":"Ubuntu:Pro:14.04:LTS","purl":"pkg:deb/ubuntu/tomcat7?arch=source&distro=esm-infra-legacy%2Ftrusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.52-1ubuntu0.16+esm2"}]}],"versions":["7.0.42-1","7.0.47-1","7.0.50-1","7.0.52-1","7.0.52-1ubuntu0.1","7.0.52-1ubuntu0.3","7.0.52-1ubuntu0.6","7.0.52-1ubuntu0.7","7.0.52-1ubuntu0.8","7.0.52-1ubuntu0.9","7.0.52-1ubuntu0.10","7.0.52-1ubuntu0.11","7.0.52-1ubuntu0.13","7.0.52-1ubuntu0.14","7.0.52-1ubuntu0.15","7.0.52-1ubuntu0.16","7.0.52-1ubuntu0.16+esm1"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro","binaries":[{"binary_version":"7.0.52-1ubuntu0.16+esm2","binary_name":"libservlet3.0-java"},{"binary_name":"libtomcat7-java","binary_version":"7.0.52-1ubuntu0.16+esm2"},{"binary_name":"tomcat7","binary_version":"7.0.52-1ubuntu0.16+esm2"},{"binary_name":"tomcat7-admin","binary_version":"7.0.52-1ubuntu0.16+esm2"},{"binary_version":"7.0.52-1ubuntu0.16+esm2","binary_name":"tomcat7-common"},{"binary_name":"tomcat7-docs","binary_version":"7.0.52-1ubuntu0.16+esm2"},{"binary_name":"tomcat7-examples","binary_version":"7.0.52-1ubuntu0.16+esm2"},{"binary_version":"7.0.52-1ubuntu0.16+esm2","binary_name":"tomcat7-user"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8383-1.json","cves_map":{"cves":[{"id":"CVE-2026-43512","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-43513","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-43515","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]}],"ecosystem":"Ubuntu:Pro:14.04:LTS"}}},{"package":{"name":"tomcat7","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/tomcat7?arch=source&distro=esm-apps-legacy%2Fxenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.68-1ubuntu0.4+esm4"}]}],"versions":["7.0.64-1","7.0.68-1","7.0.68-1ubuntu0.1","7.0.68-1ubuntu0.3","7.0.68-1ubuntu0.4","7.0.68-1ubuntu0.4+esm1","7.0.68-1ubuntu0.4+esm2","7.0.68-1ubuntu0.4+esm3"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro","binaries":[{"binary_version":"7.0.68-1ubuntu0.4+esm4","binary_name":"libservlet3.0-java"},{"binary_version":"7.0.68-1ubuntu0.4+esm4","binary_name":"libtomcat7-java"},{"binary_version":"7.0.68-1ubuntu0.4+esm4","binary_name":"tomcat7"},{"binary_name":"tomcat7-admin","binary_version":"7.0.68-1ubuntu0.4+esm4"},{"binary_version":"7.0.68-1ubuntu0.4+esm4","binary_name":"tomcat7-common"},{"binary_name":"tomcat7-docs","binary_version":"7.0.68-1ubuntu0.4+esm4"},{"binary_version":"7.0.68-1ubuntu0.4+esm4","binary_name":"tomcat7-examples"},{"binary_version":"7.0.68-1ubuntu0.4+esm4","binary_name":"tomcat7-user"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8383-1.json","cves_map":{"cves":[{"id":"CVE-2026-43512","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-43513","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-43515","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]}],"ecosystem":"Ubuntu:Pro:16.04:LTS"}}}],"schema_version":"1.7.5"}