Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h468-7pvh-8vr8

Опубликовано: 09 апр. 2026
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Apache Tomcat: Padding Oracle vulnerability in EncryptInterceptor

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109.

Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.

Пакеты

Наименование

org.apache.tomcat:tomcat-tribes

maven
Затронутые версииВерсия исправления

>= 9.0.13, < 9.0.116

9.0.116

Наименование

org.apache.tomcat:tomcat-tribes

maven
Затронутые версииВерсия исправления

>= 10.1.50, < 10.1.53

10.1.53

Наименование

org.apache.tomcat:tomcat-tribes

maven
Затронутые версииВерсия исправления

>= 11.0.0-M1, <= 11.0.18

11.0.20

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

>= 9.0.13, < 9.0.116

9.0.116

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

>= 10.1.50, < 10.1.53

10.1.53

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

>= 11.0.0-M1, <= 11.0.18

11.0.20

Наименование

org.apache.tomcat:tomcat-tribes

maven
Затронутые версииВерсия исправления

>= 8.5.38, <= 8.5.100

Отсутствует

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

>= 8.5.38, <= 8.5.100

Отсутствует

Наименование

org.apache.tomcat:tomcat-tribes

maven
Затронутые версииВерсия исправления

>= 7.0.100, <= 7.0.109

Отсутствует

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

>= 7.0.100, <= 7.0.109

Отсутствует

EPSS

Процентиль: 93%
0.06258
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-209

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.

CVSS3: 7.5
redhat
4 месяца назад

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.

CVSS3: 7.5
nvd
4 месяца назад

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.

CVSS3: 7.5
debian
4 месяца назад

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor wit ...

CVSS3: 7.5
fstec
4 месяца назад

Уязвимость сервера приложений Apache Tomcat, связанная с недостатками механизма формирования отчетов об ошибках, позволяющая нарушителю осуществить атаку типа Padding Oracle (атаку с использованием «заполнения»)

EPSS

Процентиль: 93%
0.06258
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-209