Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59084

Опубликовано: 14 июл. 2026
Источник: redhat
CVSS3: 3.8
EPSS Низкий

Описание

Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.

A flaw was found in Apache Tomcat. Insufficient technical documentation regarding the secure configuration of the EncryptInterceptor component may lead to deployments with insecure settings. This vulnerability could allow an attacker to exploit misconfigurations that arise from unclear guidance, potentially compromising the confidentiality or integrity of data processed by the affected system.

Отчет

This Low impact vulnerability in Apache Tomcat arises from insufficient documentation for the EncryptInterceptor. Without clear guidance on secure configuration, administrators might inadvertently deploy the interceptor in a way that weakens security, rather than a direct code flaw. This issue affects Red Hat products utilizing Apache Tomcat, including Red Hat Enterprise Linux and Red Hat JBoss Web Server.

Меры по смягчению последствий

To mitigate this issue, ensure that the EncryptInterceptor in Apache Tomcat is configured according to secure best practices. Review existing configurations of EncryptInterceptor to verify that all security requirements are met and that no insecure settings are in place. If the EncryptInterceptor is not actively used, no specific action is required.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10tomcatAffected
Red Hat Enterprise Linux 10tomcat9Affected
Red Hat Enterprise Linux 6tomcat6Out of support scope
Red Hat Enterprise Linux 7tomcatOut of support scope
Red Hat Enterprise Linux 8pki-deps:10.6/pki-servlet-engineAffected
Red Hat Enterprise Linux 8tomcatAffected
Red Hat Enterprise Linux 9pki-servlet-engineAffected
Red Hat Enterprise Linux 9tomcatAffected
Red Hat JBoss Web Server 5jws5-tomcatAffected
Red Hat Hardened Imagestomcat11-main-11.0.24-0.1.hum1FixedRHSA-2026:3687208.07.2026

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-1188
https://bugzilla.redhat.com/show_bug.cgi?id=2499931tomcat: Apache Tomcat: Insufficient documentation for EncryptInterceptor may lead to insecure configurations

EPSS

Процентиль: 40%
0.00506
Низкий

3.8 Low

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
17 дней назад

Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.

CVSS3: 9.1
nvd
17 дней назад

Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.

CVSS3: 9.1
debian
17 дней назад

Insufficient Technical Documentation vulnerability in Apache Tomcat si ...

CVSS3: 9.1
github
17 дней назад

Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.

EPSS

Процентиль: 40%
0.00506
Низкий

3.8 Low

CVSS3