Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-34486

Опубликовано: 09 апр. 2026
Источник: nvd
CVSS3: 7.5
EPSS Критический

Описание

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.

This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.

Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:apache:tomcat:9.0.116:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:10.1.53:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:11.0.20:*:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:a:redhat:jboss_web_server:7.0.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_els:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:10.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_tus:8.8:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:8.8:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.6:*:*:*:*:*:*:*

EPSS

Процентиль: 100%
0.98616
Критический

7.5 High

CVSS3

Дефекты

CWE-311
CWE-807

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 месяцев назад

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

CVSS3: 7.5
redhat
5 месяцев назад

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

CVSS3: 7.5
debian
5 месяцев назад

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat du ...

CVSS3: 7.5
github
5 месяцев назад

Apache Tomcat Missing Encryption of Sensitive Data vulnerability

CVSS3: 7.5
fstec
5 месяцев назад

Уязвимость сервера приложений Apache Tomcat, связанная с недостатками шифрования конфиденциальных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 100%
0.98616
Критический

7.5 High

CVSS3

Дефекты

CWE-311
CWE-807