PT-2026-31712 · Apache+1 · Apache Tomcat+1
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Tomcat version 11.0.20
Apache Tomcat version 10.1.53
Apache Tomcat version 9.0.116
Description
A flaw exists where the
EncryptInterceptor, a component designed to ensure data encryption, can be bypassed. This issue was introduced as a result of a fix for a previous vulnerability. The bypass allows sensitive data to remain unencrypted, which may lead to unauthorized access to protected information or information disclosure. In the context of Tribes clustering, the EncryptInterceptor incorrectly forwards failed decryption attempts to internal deserialization logic instead of dropping them, which could allow a remote attacker to trigger arbitrary code execution if they can reach the Tribes receiver on TCP port 4000 and the target has usable gadget classes on the classpath.Recommendations
Upgrade Apache Tomcat version 11.0.20 to 11.0.21.
Upgrade Apache Tomcat version 10.1.53 to 10.1.54.
Upgrade Apache Tomcat version 9.0.116 to 9.0.117.
Exploit
Fix
RCE
Missing Encryption of Sensitive Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Tomcat
Rocky Linux