Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-29146

Опубликовано: 09 апр. 2026
Источник: redhat
CVSS3: 7.5

Описание

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.

A flaw was found in Apache Tomcat. This Padding Oracle vulnerability, present in the EncryptInterceptor with its default configuration, could allow a remote attacker to decrypt sensitive information. By exploiting weaknesses in the encryption padding, an attacker may be able to gain unauthorized access to data that should remain confidential.

Отчет

Important: A padding oracle vulnerability exists in Apache Tomcat's EncryptInterceptor when using its default configuration. This flaw could allow a remote attacker to decrypt sensitive information by exploiting weaknesses in the encryption padding. This vulnerability is not exploitable in any supported Red Hat Products. This is due to the fact EncryptInterceptor is a Tomcat component used to encrypt communication between different nodes in a cluster, however Tomcat's clustering is not tested and supported by Red Hat since Red Hat Enterprise Linux 7. More details about Tomcat's clustering in Red Hat supported products can be found at the following Solution page:

https://access.redhat.com/solutions/67862

Меры по смягчению последствий

This vulnerability can be mitigated by removing the affected jar file from the tomcat installation. It can be achieved by running the following command as root:

systemctl stop tomcat rm -fv /usr/share/java/tomcat/catalina-tribes.jar systemctl start tomcat

It's important to notice if the Tomcat instance is configured to run with clustering, this may lead to errors when restarting the tomcat service. Red Hat's distributed Apache Tomcat should not be run with Clustering enabled, so make sure to disable such configuration before proceed with the mitigation if that's the case.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6tomcat6Out of support scope
Red Hat Enterprise Linux 8pki-deps:10.6/pki-servlet-engineWill not fix
Red Hat Enterprise Linux 9pki-servlet-engineNot affected
Red Hat JBoss Web Server 5tomcatWill not fix
Red Hat Enterprise Linux 10tomcatFixedRHSA-2026:3678808.07.2026
Red Hat Enterprise Linux 10tomcat9FixedRHSA-2026:3679008.07.2026
Red Hat Enterprise Linux 10.0 Extended Update SupporttomcatFixedRHSA-2026:3678708.07.2026
Red Hat Enterprise Linux 10.0 Extended Update Supporttomcat9FixedRHSA-2026:3678908.07.2026
Red Hat Enterprise Linux 7 Extended Lifecycle SupporttomcatFixedRHSA-2026:3850513.07.2026
Red Hat Enterprise Linux 8tomcatFixedRHSA-2026:3713709.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1240
https://bugzilla.redhat.com/show_bug.cgi?id=2457020Apache Tomcat: Apache Tomcat: Information disclosure via Padding Oracle vulnerability in EncryptInterceptor

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 месяцев назад

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.

CVSS3: 7.5
nvd
5 месяцев назад

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.

CVSS3: 7.5
debian
5 месяцев назад

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor wit ...

CVSS3: 7.5
redos
4 месяца назад

Уязвимость tomcat11

CVSS3: 7.5
redos
4 месяца назад

Уязвимость tomcat10

7.5 High

CVSS3