Описание
ELSA-2026-19054: tomcat security update (IMPORTANT)
[1:10.1.36-3.el10_1.1]
- Resolves: RHEL-150719 Certificate revocation bypass due to improper OCSP response validation (CVE-2026-24734)
[1:10.1.49-1]
- Resolves: RHEL-150099 Rebase tomcat package to enable PQC features
[1:10.1.36-4]
- Resolves: RHEL-124493 tomcat: Directory traversal via rewrite with possible RCE (CVE-2025-55752)
- Resolves: RHEL-132560 tomcat: Bypass of rules in Rewrite Valve (CVE-2025-31651)
- Resolves: RHEL-132526 tomcat: Denial of service (CVE-2025-61795)
[1:10.1.36-3]
- Resolves: RHEL-102184 tomcat: http/2 'MadeYouReset' DoS attack through HTTP/2 control frames (CVE-2025-48989)
- Resolves: RHEL-108906 tomcat: Denial of service (CVE-2025-52520)
[1:10.1.36-2]
- Resolves: RHEL-108900 tomcat: Apache FileUpload DOS via part headers (CVE-2025-48976)
- Resolves: RHEL-108902 tomcat: Dos in multipart upload (CVE-2025-48988)
- Resolves: RHEL-108904 tomcat: Security constraint bypass for pre/post-resources (CVE-2025-49125)
- Resolves: RHEL-108908 tomcat: Denial of service (CVE-2025-53506)
[1:10.1.36-1]
- Rebase tomcat to 10.1.36
- Resolves: RHEL-82925 tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT (CVE-2025-24813)
- Resolves: RHEL-87272 tomcat: DoS in examples web application (CVE-2024-54677)
- Resolves: RHEL-87273 tomcat: Authentication bypass when using Jakarta Authentication API (CVE-2024-52316)
- Resolves: RHEL-85343 - NoClassDefFoundError when using migration tool
[1:10.1.8-2]
- Resolves: RHEL-78899 Add missing Obsoletes
[1:10.1.8-1]
- Resolves: RHEL-51222 Upgrade tomcat to 10.1.8
[1:9.0.87-3]
- Bump release for October 2024 mass rebuild: Resolves: RHEL-64018
[1:9.0.87-2]
- Resolves: RHEL-50166 - Rebase tomcat to version 9.0.87
- Resolves: RHEL-12274 - Use src.zip file as a Source0 instead of tar.gz
- Resolves: RHEL-51277 - Prune changelog to remove non-relevant history
- Resolves: RHEL-52906 - tomcat: Switch to using Java 21 as the default JDK
- Resolves: RHEL-55194 - Fix changelog version
- Resolves: RHEL-46156 tomcat: Improper Handling of Exceptional Conditions (CVE-2024-34750)
Обновленные пакеты
Oracle Linux 10
Oracle Linux aarch64
tomcat
10.1.49-1.el10_2.1
tomcat-admin-webapps
10.1.49-1.el10_2.1
tomcat-docs-webapp
10.1.49-1.el10_2.1
tomcat-el-5.0-api
10.1.49-1.el10_2.1
tomcat-jsp-3.1-api
10.1.49-1.el10_2.1
tomcat-lib
10.1.49-1.el10_2.1
tomcat-servlet-6.0-api
10.1.49-1.el10_2.1
tomcat-webapps
10.1.49-1.el10_2.1
Oracle Linux x86_64
tomcat
10.1.49-1.el10_2.1
tomcat-admin-webapps
10.1.49-1.el10_2.1
tomcat-docs-webapp
10.1.49-1.el10_2.1
tomcat-el-5.0-api
10.1.49-1.el10_2.1
tomcat-jsp-3.1-api
10.1.49-1.el10_2.1
tomcat-lib
10.1.49-1.el10_2.1
tomcat-servlet-6.0-api
10.1.49-1.el10_2.1
tomcat-webapps
10.1.49-1.el10_2.1
Связанные CVE
Связанные уязвимости
Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP response which could allow certificate revocation to be bypassed. This issue affects Apache Tomcat Native: from 1.3.0 through 1.3.4, from 2.0.0 through 2.0.11; Apache Tomcat: from 11.0.0-M1 through 11.0.17, from 10.1.0-M7 through 10.1.51, from 9.0.83 through 9.0.114. The following versions were EOL at the time the CVE was created but are known to be affected: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39. Older EOL versions are not affected. Apache Tomcat Native users are recommended to upgrade to versions 1.3.5 or later or 2.0.12 or later, which fix the issue. Apache Tomcat users are recommended to upgrade to versions 11.0.18 or later, 10.1.52 or later or 9.0.115 or later which fix the issue.
Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP response which could allow certificate revocation to be bypassed. This issue affects Apache Tomcat Native: from 1.3.0 through 1.3.4, from 2.0.0 through 2.0.11; Apache Tomcat: from 11.0.0-M1 through 11.0.17, from 10.1.0-M7 through 10.1.51, from 9.0.83 through 9.0.114. The following versions were EOL at the time the CVE was created but are known to be affected: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39. Older EOL versions are not affected. Apache Tomcat Native users are recommended to upgrade to versions 1.3.5 or later or 2.0.12 or later, which fix the issue. Apache Tomcat users are recommended to upgrade to versions 11.0.18 or later, 10.1.52 or later or 9.0.115 or later which fix the issue.
Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP response which could allow certificate revocation to be bypassed. This issue affects Apache Tomcat Native: from 1.3.0 through 1.3.4, from 2.0.0 through 2.0.11; Apache Tomcat: from 11.0.0-M1 through 11.0.17, from 10.1.0-M7 through 10.1.51, from 9.0.83 through 9.0.114. The following versions were EOL at the time the CVE was created but are known to be affected: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39. Older EOL versions are not affected. Apache Tomcat Native users are recommended to upgrade to versions 1.3.5 or later or 2.0.12 or later, which fix the issue. Apache Tomcat users are recommended to upgrade to versions 11.0.18 or later, 10.1.52 or later or 9.0.115 or later which fix the issue.
Improper Input Validation vulnerability in Apache Tomcat Native, Apach ...