Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-18537

Опубликовано: 21 июл. 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-18537: tomcat security update (IMPORTANT)

[1:10.1.49-3]

  • Related: RHEL-168577 Remove unnecessary patch

[1:10.1.49-2]

  • Resolves: RHEL-168577 Remove tomcat clustering JAR from RPM builds Resolves: CVE-2026-29146 tomcat: Apache Tomcat: Information disclosure via Padding Oracle vulnerability in EncryptInterceptor Resolves: CVE-2026-34486 tomcat: Apache Tomcat: Missing Encryption of Sensitive Data due to EncryptInterceptor bypass

[1:10.1.36-3.el10_1.1]

  • Resolves: RHEL-150719 Certificate revocation bypass due to improper OCSP response validation (CVE-2026-24734)

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

tomcat

10.1.49-3.el10_2

tomcat-admin-webapps

10.1.49-3.el10_2

tomcat-docs-webapp

10.1.49-3.el10_2

tomcat-el-5.0-api

10.1.49-3.el10_2

tomcat-jsp-3.1-api

10.1.49-3.el10_2

tomcat-lib

10.1.49-3.el10_2

tomcat-servlet-6.0-api

10.1.49-3.el10_2

tomcat-webapps

10.1.49-3.el10_2

Oracle Linux x86_64

tomcat

10.1.49-3.el10_2

tomcat-admin-webapps

10.1.49-3.el10_2

tomcat-docs-webapp

10.1.49-3.el10_2

tomcat-el-5.0-api

10.1.49-3.el10_2

tomcat-jsp-3.1-api

10.1.49-3.el10_2

tomcat-lib

10.1.49-3.el10_2

tomcat-servlet-6.0-api

10.1.49-3.el10_2

tomcat-webapps

10.1.49-3.el10_2

Связанные уязвимости

rocky
2 месяца назад

Important: tomcat security update

oracle-oval
около 1 месяца назад

ELSA-2026-18916: tomcat security update (IMPORTANT)

oracle-oval
10 дней назад

ELSA-2026-18536: tomcat9 security update (IMPORTANT)

CVSS3: 7.3
ubuntu
около 1 года назад

Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that apply to the pathInfo component of a URI mapped to the CGI servlet. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.6, from 10.1.0-M1 through 10.1.40, from 9.0.0.M1 through 9.0.104. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.7, 10.1.41 or 9.0.105, which fixes the issue.

CVSS3: 6.5
redhat
около 1 года назад

Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that apply to the pathInfo component of a URI mapped to the CGI servlet. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.6, from 10.1.0-M1 through 10.1.40, from 9.0.0.M1 through 9.0.104. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.7, 10.1.41 or 9.0.105, which fixes the issue.