Описание
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.
This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
A flaw was found in Apache Tomcat. This vulnerability, categorized as Missing Encryption of Sensitive Data, arises from a bypass in the EncryptInterceptor, a component designed to ensure data encryption. This bypass, introduced as a fix for CVE-2026-29146, allows sensitive data to remain unencrypted, potentially leading to information disclosure.
Отчет
This is an Important flaw in Apache Tomcat where a bypass in the EncryptInterceptor allows sensitive data to remain unencrypted. This could lead to information disclosure in Red Hat Enterprise Linux and Red Hat JBoss Web Server environments utilizing affected versions of Apache Tomcat.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | tomcat6 | Out of support scope | ||
| Red Hat Enterprise Linux 8 | pki-deps:10.6/pki-servlet-engine | Will not fix | ||
| Red Hat Enterprise Linux 9 | pki-servlet-engine | Will not fix | ||
| Red Hat JBoss Web Server 5 | tomcat | Will not fix | ||
| Red Hat JBoss Web Server 6 | tomcat | Affected | ||
| Red Hat Enterprise Linux 10 | tomcat | Fixed | RHSA-2026:36788 | 08.07.2026 |
| Red Hat Enterprise Linux 10 | tomcat9 | Fixed | RHSA-2026:36790 | 08.07.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | tomcat | Fixed | RHSA-2026:36787 | 08.07.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | tomcat9 | Fixed | RHSA-2026:36789 | 08.07.2026 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | tomcat | Fixed | RHSA-2026:38505 | 13.07.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat du ...
Apache Tomcat Missing Encryption of Sensitive Data vulnerability
Уязвимость сервера приложений Apache Tomcat, связанная с недостатками шифрования конфиденциальных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
EPSS
7.5 High
CVSS3