{"id":"USN-8383-1","summary":"tomcat6, tomcat7 vulnerabilities","details":"It was discovered that Tomcat incorrectly handled digest\nauthentication. A remote attacker could possibly use this issue to\nbypass authentication restrictions. (CVE-2026-43512)\n\nIt was discovered that Tomcat incorrectly handled case sensitivity\nin LockOutRealm. A remote attacker could possibly use this issue to\nbypass account lockout protections and obtain sensitive information.\n(CVE-2026-43513)\n\nIt was discovered that Tomcat incorrectly handled authorization when\nmultiple method constraints defined the same HTTP method. A remote\nattacker could possibly use this issue to bypass authorization\nrestrictions. (CVE-2026-43515)","modified":"2026-06-05T11:29:09.937655868Z","published":"2026-06-04T13:15:22Z","related":["UBUNTU-CVE-2026-43512","UBUNTU-CVE-2026-43513","UBUNTU-CVE-2026-43515"],"upstream":["UBUNTU-CVE-2026-43512","UBUNTU-CVE-2026-43513","UBUNTU-CVE-2026-43515"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8383-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-43512"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-43513"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-43515"}],"affected":[{"package":{"name":"tomcat6","ecosystem":"Ubuntu:Pro:14.04:LTS","purl":"pkg:deb/ubuntu/tomcat6?arch=source&distro=esm-infra-legacy%2Ftrusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.39-1ubuntu0.1+esm3"}]}],"versions":["6.0.37-1","6.0.39-1","6.0.39-1ubuntu0.1","6.0.39-1ubuntu0.1+esm1","6.0.39-1ubuntu0.1+esm2"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro","binaries":[{"binary_name":"libservlet2.4-java","binary_version":"6.0.39-1ubuntu0.1+esm3"},{"binary_name":"libservlet2.5-java","binary_version":"6.0.39-1ubuntu0.1+esm3"},{"binary_name":"libtomcat6-java","binary_version":"6.0.39-1ubuntu0.1+esm3"},{"binary_name":"tomcat6","binary_version":"6.0.39-1ubuntu0.1+esm3"},{"binary_name":"tomcat6-admin","binary_version":"6.0.39-1ubuntu0.1+esm3"},{"binary_name":"tomcat6-common","binary_version":"6.0.39-1ubuntu0.1+esm3"},{"binary_name":"tomcat6-docs","binary_version":"6.0.39-1ubuntu0.1+esm3"},{"binary_name":"tomcat6-examples","binary_version":"6.0.39-1ubuntu0.1+esm3"},{"binary_name":"tomcat6-extras","binary_version":"6.0.39-1ubuntu0.1+esm3"},{"binary_name":"tomcat6-user","binary_version":"6.0.39-1ubuntu0.1+esm3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8383-1.json","cves_map":{"ecosystem":"Ubuntu:Pro:14.04:LTS","cves":[{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-43512"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-43513"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-43515"}]}}},{"package":{"name":"tomcat7","ecosystem":"Ubuntu:Pro:14.04:LTS","purl":"pkg:deb/ubuntu/tomcat7?arch=source&distro=esm-infra-legacy%2Ftrusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.52-1ubuntu0.16+esm2"}]}],"versions":["7.0.42-1","7.0.47-1","7.0.50-1","7.0.52-1","7.0.52-1ubuntu0.1","7.0.52-1ubuntu0.3","7.0.52-1ubuntu0.6","7.0.52-1ubuntu0.7","7.0.52-1ubuntu0.8","7.0.52-1ubuntu0.9","7.0.52-1ubuntu0.10","7.0.52-1ubuntu0.11","7.0.52-1ubuntu0.13","7.0.52-1ubuntu0.14","7.0.52-1ubuntu0.15","7.0.52-1ubuntu0.16","7.0.52-1ubuntu0.16+esm1"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro","binaries":[{"binary_name":"libservlet3.0-java","binary_version":"7.0.52-1ubuntu0.16+esm2"},{"binary_name":"libtomcat7-java","binary_version":"7.0.52-1ubuntu0.16+esm2"},{"binary_name":"tomcat7","binary_version":"7.0.52-1ubuntu0.16+esm2"},{"binary_name":"tomcat7-admin","binary_version":"7.0.52-1ubuntu0.16+esm2"},{"binary_name":"tomcat7-common","binary_version":"7.0.52-1ubuntu0.16+esm2"},{"binary_name":"tomcat7-docs","binary_version":"7.0.52-1ubuntu0.16+esm2"},{"binary_name":"tomcat7-examples","binary_version":"7.0.52-1ubuntu0.16+esm2"},{"binary_name":"tomcat7-user","binary_version":"7.0.52-1ubuntu0.16+esm2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8383-1.json","cves_map":{"ecosystem":"Ubuntu:Pro:14.04:LTS","cves":[{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-43512"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-43513"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-43515"}]}}},{"package":{"name":"tomcat7","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/tomcat7?arch=source&distro=esm-apps-legacy%2Fxenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.68-1ubuntu0.4+esm4"}]}],"versions":["7.0.64-1","7.0.68-1","7.0.68-1ubuntu0.1","7.0.68-1ubuntu0.3","7.0.68-1ubuntu0.4","7.0.68-1ubuntu0.4+esm1","7.0.68-1ubuntu0.4+esm2","7.0.68-1ubuntu0.4+esm3"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro","binaries":[{"binary_name":"libservlet3.0-java","binary_version":"7.0.68-1ubuntu0.4+esm4"},{"binary_name":"libtomcat7-java","binary_version":"7.0.68-1ubuntu0.4+esm4"},{"binary_name":"tomcat7","binary_version":"7.0.68-1ubuntu0.4+esm4"},{"binary_name":"tomcat7-admin","binary_version":"7.0.68-1ubuntu0.4+esm4"},{"binary_name":"tomcat7-common","binary_version":"7.0.68-1ubuntu0.4+esm4"},{"binary_name":"tomcat7-docs","binary_version":"7.0.68-1ubuntu0.4+esm4"},{"binary_name":"tomcat7-examples","binary_version":"7.0.68-1ubuntu0.4+esm4"},{"binary_name":"tomcat7-user","binary_version":"7.0.68-1ubuntu0.4+esm4"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8383-1.json","cves_map":{"ecosystem":"Ubuntu:Pro:16.04:LTS","cves":[{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-43512"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-43513"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-43515"}]}}}],"schema_version":"1.7.5"}