Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.13 through 9.0.18, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109.
Users are recommended to upgrade to version 11.0.23, 10.1.56, 9.0.119, which fixes the issue.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade tomcat-servlet-4.0-apiUpgrade tomcat-admin-webappsUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-docs-webappUpgrade tomcatUpgrade tomcat-el-3.0-apiUpgrade tomcat-libUpgrade tomcat-jsvcUpgrade tomcat-webapps | Jul 21, 2026 | Jul 21, 2026 |
| Apache Tomcat | — | Upgrade Apache Tomcat to 9.0.119Upgrade Apache Tomcat to the latest available versionUpgrade Apache Tomcat to 11.0.23Upgrade Apache Tomcat to 10.1.56 | Jun 30, 2026 | Jun 29, 2026 |
| Debian | — | Upgrade tomcat9 | Jul 1, 2026 | Jul 1, 2026 |
| Redhat_linux | — | Upgrade tomcat-admin-webappsUpgrade tomcat-libUpgrade tomcat-servlet-4.0-apiUpgrade tomcat-webappsUpgrade tomcat9-libUpgrade tomcat9-el-3.0-apiUpgrade tomcat-jsp-2.3-apiUpgrade tomcat9-admin-webappsNo solution existsUpgrade tomcat9-jsp-2.3-apiUpgrade tomcat9-servlet-4.0-apiUpgrade tomcat9-docs-webappUpgrade tomcat-docs-webappUpgrade tomcat9-webappsUpgrade tomcat-el-3.0-apiUpgrade tomcatUpgrade tomcat9 | Jul 17, 2026 | Jun 29, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub