Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:37137

Опубликовано: 10 июл. 2026
Источник: rocky
Оценка: Important

Описание

Important: tomcat security, bug fix, and enhancement update

Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies.

Security Fix(es):

  • Apache Tomcat: Apache Tomcat: Information disclosure via Padding Oracle vulnerability in EncryptInterceptor (CVE-2026-29146)

  • Apache Tomcat: Apache Tomcat: Missing Encryption of Sensitive Data due to EncryptInterceptor bypass (CVE-2026-34486)

Bug Fix(es) and Enhancement(s):

  • Remove tomcat clustering JAR from RPM builds (JIRA:Rocky Linux-183993)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
tomcatnoarch2.el8_10tomcat-9.0.87-2.el8_10.noarch.rpm
tomcat-admin-webappsnoarch2.el8_10tomcat-admin-webapps-9.0.87-2.el8_10.noarch.rpm
tomcat-docs-webappnoarch2.el8_10tomcat-docs-webapp-9.0.87-2.el8_10.noarch.rpm
tomcat-el-3.0-apinoarch2.el8_10tomcat-el-3.0-api-9.0.87-2.el8_10.noarch.rpm
tomcat-jsp-2.3-apinoarch2.el8_10tomcat-jsp-2.3-api-9.0.87-2.el8_10.noarch.rpm
tomcat-libnoarch2.el8_10tomcat-lib-9.0.87-2.el8_10.noarch.rpm
tomcat-servlet-4.0-apinoarch2.el8_10tomcat-servlet-4.0-api-9.0.87-2.el8_10.noarch.rpm
tomcat-webappsnoarch2.el8_10tomcat-webapps-9.0.87-2.el8_10.noarch.rpm

Показывать по

Связанные CVE

Связанные уязвимости

rocky
21 день назад

Important: tomcat security, bug fix, and enhancement update

rocky
21 день назад

Important: tomcat security, bug fix, and enhancement update

oracle-oval
22 дня назад

ELSA-2026-37137: tomcat security, bug fix, and enhancement update (IMPORTANT)

oracle-oval
23 дня назад

ELSA-2026-36879: tomcat security, bug fix, and enhancement update (IMPORTANT)

oracle-oval
15 дней назад

ELSA-2026-36790: tomcat9 security, bug fix, and enhancement update (IMPORTANT)