Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h468-7pvh-8vr8

Опубликовано: 09 апр. 2026
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Apache Tomcat: Padding Oracle vulnerability in EncryptInterceptor

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109.

Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.

Пакеты

Наименование

org.apache.tomcat:tomcat-tribes

maven
Затронутые версииВерсия исправления

>= 9.0.13, < 9.0.116

9.0.116

Наименование

org.apache.tomcat:tomcat-tribes

maven
Затронутые версииВерсия исправления

>= 10.1.50, < 10.1.53

10.1.53

Наименование

org.apache.tomcat:tomcat-tribes

maven
Затронутые версииВерсия исправления

>= 11.0.0-M1, <= 11.0.18

11.0.20

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

>= 9.0.13, < 9.0.116

9.0.116

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

>= 10.1.50, < 10.1.53

10.1.53

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

>= 11.0.0-M1, <= 11.0.18

11.0.20

Наименование

org.apache.tomcat:tomcat-tribes

maven
Затронутые версииВерсия исправления

>= 8.5.38, <= 8.5.100

Отсутствует

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

>= 8.5.38, <= 8.5.100

Отсутствует

Наименование

org.apache.tomcat:tomcat-tribes

maven
Затронутые версииВерсия исправления

>= 7.0.100, <= 7.0.109

Отсутствует

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

>= 7.0.100, <= 7.0.109

Отсутствует

EPSS

Процентиль: 95%
0.0885
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-209

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 месяцев назад

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.

CVSS3: 7.5
redhat
5 месяцев назад

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.

CVSS3: 7.5
nvd
5 месяцев назад

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.

CVSS3: 7.5
debian
5 месяцев назад

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor wit ...

CVSS3: 7.5
redos
4 месяца назад

Уязвимость tomcat11

EPSS

Процентиль: 95%
0.0885
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-209