Apache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.5epss 6.3%
probabilidad de explotación
6.3%top 7% de las CVE
explotación observada
noninguna fuente lo reporta
Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109.
Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Productos afectados
Apache Software Foundation · Apache TomcatReferencias
https://access.redhat.com/errata/RHSA-2026:20405https://access.redhat.com/errata/RHSA-2026:20406https://access.redhat.com/errata/RHSA-2026:36787https://access.redhat.com/errata/RHSA-2026:36788https://access.redhat.com/errata/RHSA-2026:36789https://access.redhat.com/errata/RHSA-2026:36790https://access.redhat.com/errata/RHSA-2026:36876https://access.redhat.com/errata/RHSA-2026:36877https://access.redhat.com/errata/RHSA-2026:36878https://access.redhat.com/errata/RHSA-2026:36879https://access.redhat.com/errata/RHSA-2026:37136https://access.redhat.com/errata/RHSA-2026:37137