PT-2026-31700 · Apache+3 · Apache Tomcat+3
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Tomcat versions 11.0.0-M1 through 11.0.18
Apache Tomcat versions 10.0.0-M1 through 10.1.52
Apache Tomcat versions 9.0.13 through 9.115
Apache Tomcat versions 8.5.38 through 8.5.100
Apache Tomcat versions 7.0.100 through 7.0.109
Description
A Padding Oracle flaw exists in the
EncryptInterceptor when using its default configuration. This issue stems from the use of Cipher Block Chaining (CBC) and deficiencies in the error reporting mechanism. A remote attacker can exploit these weaknesses in the encryption padding to decrypt sensitive information and gain unauthorized access to confidential data.Recommendations
Upgrade Apache Tomcat versions 11.0.0-M1 through 11.0.18 to version 11.0.19.
Upgrade Apache Tomcat versions 10.0.0-M1 through 10.1.52 to version 10.1.53.
Upgrade Apache Tomcat versions 9.0.13 through 9.115 to version 9.0.116.
At the moment, there is no information about a newer version that contains a fix for Apache Tomcat versions 8.5.38 through 8.5.100.
At the moment, there is no information about a newer version that contains a fix for Apache Tomcat versions 7.0.100 through 7.0.109.
Exploit
Fix
DoS
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Tomcat
Confluence
Red Os
Rocky Linux