REDHAT-BUG-2457027: High severity Apache Tomcat vulnerability
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.
This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.0.21 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.1.54 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.0.117
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2457027?
The severity of REDHAT-BUG-2457027 is high, rated at 7.
What impact does REDHAT-BUG-2457027 have on Apache Tomcat users?
REDHAT-BUG-2457027 leads to missing encryption of sensitive data, posing a significant risk to users.
How do I fix REDHAT-BUG-2457027?
To fix REDHAT-BUG-2457027, users should upgrade to Apache Tomcat versions 11.0.21, 10.1.54, or 9.0.117.
Which versions of Apache Tomcat are affected by REDHAT-BUG-2457027?
Affected versions of Apache Tomcat include 11.0.20, 10.1.53, and 9.0.116.
What caused the vulnerability REDHAT-BUG-2457027?
The vulnerability REDHAT-BUG-2457027 was caused by a fix for CVE-2026-29146 that allowed the bypass of the EncryptInterceptor.