DLP and Apache Tomcat 9 Authentication Bypass Vulnerability (CVE-2024-52316)
search cancel

DLP and Apache Tomcat 9 Authentication Bypass Vulnerability (CVE-2024-52316)

book

Article ID: 430215

calendar_today

Updated On:

Products

Data Loss Prevention

Issue/Introduction

Tomcat CVE-2024-52316: Apache Tomcat 9 Authentication Bypass Vulnerability.
Is DLP vulnerable to this CVE?

 

Environment

Symantec DLP 16.0.X

Cause

CVE-2024-52316 - Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception during the authentication process without explicitly setting an HTTP status to indicate failure, the authentication may not fail, allowing the user to bypass the authentication process.

Resolution

DLP Does not use Jakarta Authentication.