Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-36790

Опубликовано: 16 июл. 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-36790: tomcat9 security, bug fix, and enhancement update (IMPORTANT)

[1:9.0.117-2]

  • Resolves: RHEL-185571 Remove tomcat clustering JAR from RPM builds

[1:9.0.117-1]

  • Resolves: RHEL-150720 Tomcat: Certificate revocation bypass due to improper OCSP response validation (CVE-2026-24734)
  • Resolves: Tomcat: OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled (CVE-2026-34500)
  • Resolves: Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer token (CVE-2026-34487)
  • Resolves: Tomcat: The fix for CVE-2026-29146 allowed the bypass of the EncryptInterceptor (CVE-2026-34486)
  • Resolves: Tomcat: Incomplete escaping of JSON access logs (CVE-2026-34483)
  • Resolves: Tomcat: The fix for CVE-2025-66614 was incomplete (CVE-2026-32990)
  • Resolves: Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default (CVE-2026-29146)
  • Resolves: Tomcat: OCSP checks sometimes soft-fail even when soft-fail is disabled (CVE-2026-29145)
  • Resolves: Tomcat: Configured TLS cipher preference order not preserved (CVE-2026-29129)
  • Resolves: Tomcat: Occasionally open redirect (CVE-2026-25854)
  • Resolves: Tomcat: Request smuggling via invalid chunk extension (CVE-2026-24880)
  • Resolves: Tomcat: Incomplete OCSP verification checks (CVE-2026-24734)
  • Resolves: Tomcat: Security constraint bypass (CVE-2026-24733)
  • Resolves: Tomcat: Client certificate verification bypass due to virtual host mapping (CVE-2025-66614)

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

tomcat9

9.0.117-2.el10_2

tomcat9-admin-webapps

9.0.117-2.el10_2

tomcat9-docs-webapp

9.0.117-2.el10_2

tomcat9-el-3.0-api

9.0.117-2.el10_2

tomcat9-jsp-2.3-api

9.0.117-2.el10_2

tomcat9-lib

9.0.117-2.el10_2

tomcat9-servlet-4.0-api

9.0.117-2.el10_2

tomcat9-webapps

9.0.117-2.el10_2

Oracle Linux x86_64

tomcat9

9.0.117-2.el10_2

tomcat9-admin-webapps

9.0.117-2.el10_2

tomcat9-docs-webapp

9.0.117-2.el10_2

tomcat9-el-3.0-api

9.0.117-2.el10_2

tomcat9-jsp-2.3-api

9.0.117-2.el10_2

tomcat9-lib

9.0.117-2.el10_2

tomcat9-servlet-4.0-api

9.0.117-2.el10_2

tomcat9-webapps

9.0.117-2.el10_2

Связанные CVE

Связанные уязвимости

rocky
21 день назад

Important: tomcat security, bug fix, and enhancement update

rocky
21 день назад

Important: tomcat security, bug fix, and enhancement update

rocky
21 день назад

Important: tomcat security, bug fix, and enhancement update

oracle-oval
22 дня назад

ELSA-2026-37137: tomcat security, bug fix, and enhancement update (IMPORTANT)

oracle-oval
23 дня назад

ELSA-2026-36879: tomcat security, bug fix, and enhancement update (IMPORTANT)