The vendor explicitly identifies these products as affected by this CVE.
- tomcat as a component of Red Hat Enterprise Linux 10
- tomcat-admin-webapps as a component of Red Hat Enterprise Linux 10
- tomcat-docs-webapp as a component of Red Hat Enterprise Linux 10
- tomcat-el-5.0-api as a component of Red Hat Enterprise Linux 10
- tomcat-jsp-3.1-api as a component of Red Hat Enterprise Linux 10
- tomcat-lib as a component of Red Hat Enterprise Linux 10
- tomcat-servlet-6.0-api as a component of Red Hat Enterprise Linux 10
- tomcat-webapps as a component of Red Hat Enterprise Linux 10
- tomcat.src as a component of Red Hat Enterprise Linux 10
- tomcat9 as a component of Red Hat Enterprise Linux 10
- tomcat9-admin-webapps as a component of Red Hat Enterprise Linux 10
- tomcat9-docs-webapp as a component of Red Hat Enterprise Linux 10
- Summary
- In Apache Tomcat, LockOutRealm mishandled case sensitivity in usernames, resulting in less effective blocking of brute force attacks.
- Remediation
- Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
