Описание
ELSA-2026-36788: tomcat security, bug fix, and enhancement update (IMPORTANT)
[1:10.1.49-3]
- Related: RHEL-168577 Remove unnecessary patch
[1:10.1.49-2]
- Resolves: RHEL-168577 Remove tomcat clustering JAR from RPM builds Resolves: CVE-2026-29146 tomcat: Apache Tomcat: Information disclosure via Padding Oracle vulnerability in EncryptInterceptor Resolves: CVE-2026-34486 tomcat: Apache Tomcat: Missing Encryption of Sensitive Data due to EncryptInterceptor bypass
[1:10.1.36-3.el10_1.1]
- Resolves: RHEL-150719 Certificate revocation bypass due to improper OCSP response validation (CVE-2026-24734)
Обновленные пакеты
Oracle Linux 10
Oracle Linux aarch64
tomcat
10.1.49-3.el10_2
tomcat-admin-webapps
10.1.49-3.el10_2
tomcat-docs-webapp
10.1.49-3.el10_2
tomcat-el-5.0-api
10.1.49-3.el10_2
tomcat-jsp-3.1-api
10.1.49-3.el10_2
tomcat-lib
10.1.49-3.el10_2
tomcat-servlet-6.0-api
10.1.49-3.el10_2
tomcat-webapps
10.1.49-3.el10_2
Oracle Linux x86_64
tomcat
10.1.49-3.el10_2
tomcat-admin-webapps
10.1.49-3.el10_2
tomcat-docs-webapp
10.1.49-3.el10_2
tomcat-el-5.0-api
10.1.49-3.el10_2
tomcat-jsp-3.1-api
10.1.49-3.el10_2
tomcat-lib
10.1.49-3.el10_2
tomcat-servlet-6.0-api
10.1.49-3.el10_2
tomcat-webapps
10.1.49-3.el10_2