Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-34486

Опубликовано: 09 апр. 2026
Источник: redhat
CVSS3: 7.5
EPSS Средний

Описание

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

A flaw was found in Apache Tomcat. This vulnerability, categorized as Missing Encryption of Sensitive Data, arises from a bypass in the EncryptInterceptor, a component designed to ensure data encryption. This bypass, introduced as a fix for CVE-2026-29146, allows sensitive data to remain unencrypted, potentially leading to information disclosure.

Отчет

This is an Important flaw in Apache Tomcat where a bypass in the EncryptInterceptor allows sensitive data to remain unencrypted. This could lead to information disclosure in Red Hat Enterprise Linux and Red Hat JBoss Web Server environments utilizing affected versions of Apache Tomcat.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6tomcat6Out of support scope
Red Hat Enterprise Linux 8pki-deps:10.6/pki-servlet-engineWill not fix
Red Hat Enterprise Linux 9pki-servlet-engineWill not fix
Red Hat JBoss Web Server 5tomcatWill not fix
Red Hat JBoss Web Server 6tomcatAffected
Red Hat Enterprise Linux 10tomcatFixedRHSA-2026:3678808.07.2026
Red Hat Enterprise Linux 10tomcat9FixedRHSA-2026:3679008.07.2026
Red Hat Enterprise Linux 10.0 Extended Update SupporttomcatFixedRHSA-2026:3678708.07.2026
Red Hat Enterprise Linux 10.0 Extended Update Supporttomcat9FixedRHSA-2026:3678908.07.2026
Red Hat Enterprise Linux 7 Extended Lifecycle SupporttomcatFixedRHSA-2026:3850513.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-807
https://bugzilla.redhat.com/show_bug.cgi?id=2457027Apache Tomcat: Apache Tomcat: Missing Encryption of Sensitive Data due to EncryptInterceptor bypass

EPSS

Процентиль: 99%
0.42627
Средний

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

CVSS3: 7.5
nvd
4 месяца назад

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

CVSS3: 7.5
debian
4 месяца назад

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat du ...

CVSS3: 7.5
github
4 месяца назад

Apache Tomcat Missing Encryption of Sensitive Data vulnerability

CVSS3: 7.5
fstec
4 месяца назад

Уязвимость сервера приложений Apache Tomcat, связанная с недостатками шифрования конфиденциальных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 99%
0.42627
Средний

7.5 High

CVSS3