Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-34486

Опубликовано: 09 апр. 2026
Источник: nvd
CVSS3: 7.5
EPSS Средний

Описание

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.

This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.

Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:apache:tomcat:9.0.116:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:10.1.53:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:11.0.20:*:*:*:*:*:*:*

EPSS

Процентиль: 99%
0.42627
Средний

7.5 High

CVSS3

Дефекты

CWE-311
CWE-807

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

CVSS3: 7.5
redhat
4 месяца назад

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

CVSS3: 7.5
debian
4 месяца назад

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat du ...

CVSS3: 7.5
github
4 месяца назад

Apache Tomcat Missing Encryption of Sensitive Data vulnerability

CVSS3: 7.5
fstec
4 месяца назад

Уязвимость сервера приложений Apache Tomcat, связанная с недостатками шифрования конфиденциальных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 99%
0.42627
Средний

7.5 High

CVSS3

Дефекты

CWE-311
CWE-807