Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-11870

Опубликовано: 29 июн. 2026
Источник: fstec
CVSS3: 6.5
CVSS2: 6.4
EPSS Низкий

Описание

Уязвимость сервера приложений Apache Tomcat связана с недостатками процедуры авторизации. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, получить несанкционированный доступ к защищаемой информации

Вендор

Red Hat, Inc.
ООО «Ред Софт»
Apache Software Foundation

Наименование ПО

Red Hat Enterprise Linux
РЕД ОС
Red Hat Hardened Images
Tomcat
Jboss Web Server

Версия ПО

8 (Red Hat Enterprise Linux)
7.3 (РЕД ОС)
9 (Red Hat Enterprise Linux)
10 (Red Hat Enterprise Linux)
8.0 (РЕД ОС)
- (Red Hat Hardened Images)
от 8.5.0 до 8.5.100 включительно (Tomcat)
от 7.0.0 до 7.0.109 включительно (Tomcat)
от 11.0.0-M1 до 11.0.22 включительно (Tomcat)
от 10.1.0-M1 до 10.1.55 включительно (Tomcat)
от 9.0.0.M1 до 9.0.118 включительно (Tomcat)
6.2.4 (Jboss Web Server)
6.2 on RHEL 10 (Jboss Web Server)
6.2 on RHEL 8 (Jboss Web Server)
6.2 on RHEL 9 (Jboss Web Server)
7.0.0 (Jboss Web Server)
7.0 on RHEL 10 (Jboss Web Server)
7.0 on RHEL 8 (Jboss Web Server)
7.0 on RHEL 9 (Jboss Web Server)

Тип ПО

Операционная система
Прикладное ПО информационных систем
Сетевое программное средство

Операционные системы и аппаратные платформы

Red Hat, Inc. Red Hat Enterprise Linux 8
ООО «Ред Софт» РЕД ОС 7.3
Red Hat, Inc. Red Hat Enterprise Linux 9
Red Hat, Inc. Red Hat Enterprise Linux 10
ООО «Ред Софт» РЕД ОС 8.0

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 6,4)
Средний уровень опасности (базовая оценка CVSS 3.1 составляет 6,5)

Возможные меры по устранению уязвимости

Использование рекомендаций производителя:
https://lists.apache.org/thread/dcjdcnnnww9hhdm016hr0l7hpw1bzjfp
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/cve-2026-55956
Для Ред ОС: http://repo.red-soft.ru/redos/8.0/x86_64/updates/
Для Ред ОС: http://repo.red-soft.ru/redos/8.0/x86_64/updates/
Для Ред ОС: http://repo.red-soft.ru/redos/7.3c/x86_64/updates/
Для Ред ОС: http://repo.red-soft.ru/redos/8.0/x86_64/updates/
Для Ред ОС: http://repo.red-soft.ru/redos/7.3c/x86_64/updates/
Для Ред ОС: http://repo.red-soft.ru/redos/7.3c/x86_64/updates/

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 73%
0.01531
Низкий

6.5 Medium

CVSS3

6.4 Medium

CVSS2

Связанные уязвимости

CVSS3: 6.5
redos
27 дней назад

Уязвимость tomcat11

CVSS3: 6.5
redos
27 дней назад

Уязвимость tomcat10

CVSS3: 6.5
redos
27 дней назад

Уязвимость tomcat

CVSS3: 6.5
ubuntu
3 месяца назад

Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.

CVSS3: 6.5
redhat
3 месяца назад

Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.

EPSS

Процентиль: 73%
0.01531
Низкий

6.5 Medium

CVSS3

6.4 Medium

CVSS2