Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-19054

Опубликовано: 08 июл. 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-19054: tomcat security update (IMPORTANT)

[1:10.1.36-3.el10_1.1]

  • Resolves: RHEL-150719 Certificate revocation bypass due to improper OCSP response validation (CVE-2026-24734)

[1:10.1.49-1]

  • Resolves: RHEL-150099 Rebase tomcat package to enable PQC features

[1:10.1.36-4]

  • Resolves: RHEL-124493 tomcat: Directory traversal via rewrite with possible RCE (CVE-2025-55752)
  • Resolves: RHEL-132560 tomcat: Bypass of rules in Rewrite Valve (CVE-2025-31651)
  • Resolves: RHEL-132526 tomcat: Denial of service (CVE-2025-61795)

[1:10.1.36-3]

  • Resolves: RHEL-102184 tomcat: http/2 'MadeYouReset' DoS attack through HTTP/2 control frames (CVE-2025-48989)
  • Resolves: RHEL-108906 tomcat: Denial of service (CVE-2025-52520)

[1:10.1.36-2]

  • Resolves: RHEL-108900 tomcat: Apache FileUpload DOS via part headers (CVE-2025-48976)
  • Resolves: RHEL-108902 tomcat: Dos in multipart upload (CVE-2025-48988)
  • Resolves: RHEL-108904 tomcat: Security constraint bypass for pre/post-resources (CVE-2025-49125)
  • Resolves: RHEL-108908 tomcat: Denial of service (CVE-2025-53506)

[1:10.1.36-1]

  • Rebase tomcat to 10.1.36
  • Resolves: RHEL-82925 tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT (CVE-2025-24813)
  • Resolves: RHEL-87272 tomcat: DoS in examples web application (CVE-2024-54677)
  • Resolves: RHEL-87273 tomcat: Authentication bypass when using Jakarta Authentication API (CVE-2024-52316)
  • Resolves: RHEL-85343 - NoClassDefFoundError when using migration tool

[1:10.1.8-2]

  • Resolves: RHEL-78899 Add missing Obsoletes

[1:10.1.8-1]

  • Resolves: RHEL-51222 Upgrade tomcat to 10.1.8

[1:9.0.87-3]

  • Bump release for October 2024 mass rebuild: Resolves: RHEL-64018

[1:9.0.87-2]

  • Resolves: RHEL-50166 - Rebase tomcat to version 9.0.87
  • Resolves: RHEL-12274 - Use src.zip file as a Source0 instead of tar.gz
  • Resolves: RHEL-51277 - Prune changelog to remove non-relevant history
  • Resolves: RHEL-52906 - tomcat: Switch to using Java 21 as the default JDK
  • Resolves: RHEL-55194 - Fix changelog version
  • Resolves: RHEL-46156 tomcat: Improper Handling of Exceptional Conditions (CVE-2024-34750)

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

tomcat

10.1.49-1.el10_2.1

tomcat-admin-webapps

10.1.49-1.el10_2.1

tomcat-docs-webapp

10.1.49-1.el10_2.1

tomcat-el-5.0-api

10.1.49-1.el10_2.1

tomcat-jsp-3.1-api

10.1.49-1.el10_2.1

tomcat-lib

10.1.49-1.el10_2.1

tomcat-servlet-6.0-api

10.1.49-1.el10_2.1

tomcat-webapps

10.1.49-1.el10_2.1

Oracle Linux x86_64

tomcat

10.1.49-1.el10_2.1

tomcat-admin-webapps

10.1.49-1.el10_2.1

tomcat-docs-webapp

10.1.49-1.el10_2.1

tomcat-el-5.0-api

10.1.49-1.el10_2.1

tomcat-jsp-3.1-api

10.1.49-1.el10_2.1

tomcat-lib

10.1.49-1.el10_2.1

tomcat-servlet-6.0-api

10.1.49-1.el10_2.1

tomcat-webapps

10.1.49-1.el10_2.1

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 месяцев назад

Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP response which could allow certificate revocation to be bypassed. This issue affects Apache Tomcat Native:  from 1.3.0 through 1.3.4, from 2.0.0 through 2.0.11; Apache Tomcat: from 11.0.0-M1 through 11.0.17, from 10.1.0-M7 through 10.1.51, from 9.0.83 through 9.0.114. The following versions were EOL at the time the CVE was created but are known to be affected: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39. Older EOL versions are not affected. Apache Tomcat Native users are recommended to upgrade to versions 1.3.5 or later or 2.0.12 or later, which fix the issue. Apache Tomcat users are recommended to upgrade to versions 11.0.18 or later, 10.1.52 or later or 9.0.115 or later which fix the issue.

CVSS3: 7.4
redhat
5 месяцев назад

Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP response which could allow certificate revocation to be bypassed. This issue affects Apache Tomcat Native:  from 1.3.0 through 1.3.4, from 2.0.0 through 2.0.11; Apache Tomcat: from 11.0.0-M1 through 11.0.17, from 10.1.0-M7 through 10.1.51, from 9.0.83 through 9.0.114. The following versions were EOL at the time the CVE was created but are known to be affected: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39. Older EOL versions are not affected. Apache Tomcat Native users are recommended to upgrade to versions 1.3.5 or later or 2.0.12 or later, which fix the issue. Apache Tomcat users are recommended to upgrade to versions 11.0.18 or later, 10.1.52 or later or 9.0.115 or later which fix the issue.

CVSS3: 7.5
nvd
5 месяцев назад

Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP response which could allow certificate revocation to be bypassed. This issue affects Apache Tomcat Native:  from 1.3.0 through 1.3.4, from 2.0.0 through 2.0.11; Apache Tomcat: from 11.0.0-M1 through 11.0.17, from 10.1.0-M7 through 10.1.51, from 9.0.83 through 9.0.114. The following versions were EOL at the time the CVE was created but are known to be affected: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39. Older EOL versions are not affected. Apache Tomcat Native users are recommended to upgrade to versions 1.3.5 or later or 2.0.12 or later, which fix the issue. Apache Tomcat users are recommended to upgrade to versions 11.0.18 or later, 10.1.52 or later or 9.0.115 or later which fix the issue.

CVSS3: 7.5
debian
5 месяцев назад

Improper Input Validation vulnerability in Apache Tomcat Native, Apach ...

rocky
около 1 месяца назад

Important: tomcat security update