The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade tomcat-libUpgrade tomcat-servlet-3.1-apiUpgrade tomcat-webappsUpgrade tomcat-jsvcUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-docs-webappUpgrade tomcatUpgrade tomcat-javadocUpgrade tomcat-admin-webappsUpgrade tomcat-el-3.0-api | Sep 28, 2023 | May 12, 2022 |
| Amazon_linux | — | Upgrade tomcat8 | Aug 5, 2022 | May 12, 2022 |
| Apache Tomcat | — | Upgrade Apache Tomcat to the latest available versionUpgrade Apache Tomcat to 8.5.79Upgrade Apache Tomcat to 10.0.21Upgrade Apache Tomcat to 10.1.0Upgrade Apache Tomcat to 9.0.63 | May 12, 2022 | May 12, 2022 |
| Debian | — | Upgrade tomcat9 | Oct 28, 2022 | May 12, 2022 |
| Red Hat Jboss Eap | — | — | Sep 19, 2024 | May 10, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 12, 2022 |
| Ubuntu | — | Upgrade tomcat9-docsUpgrade tomcat9 (Ubuntu Pro)Upgrade libtomcat8-java (Ubuntu Pro)Upgrade libtomcat9-javaUpgrade libtomcat9-java (Ubuntu Pro)Upgrade tomcat8-docs (Ubuntu Pro)Upgrade tomcat8 (Ubuntu Pro)Upgrade tomcat9Upgrade tomcat9-docs (Ubuntu Pro) | Aug 2, 2024 | May 12, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub