Configured cipher preference order not preserved vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115.
Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade tomcat-admin-webappsUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-webappsUpgrade tomcat-servlet-4.0-apiUpgrade tomcat-libUpgrade tomcat-el-3.0-apiUpgrade tomcat-jsvcUpgrade tomcat-docs-webappUpgrade tomcat | May 20, 2026 | May 20, 2026 |
| Apache Tomcat | — | Upgrade Apache Tomcat to 9.0.116Upgrade Apache Tomcat to 10.1.53Upgrade Apache Tomcat to 11.0.20Upgrade Apache Tomcat to the latest available version | Apr 10, 2026 | Apr 9, 2026 |
| Atlassian Jira | — | Upgrade to the latest version of Atlassian JIRA | May 20, 2026 | May 19, 2026 |
| Debian | — | Upgrade tomcat10Upgrade tomcat11Upgrade tomcat9 | Apr 13, 2026 | Apr 13, 2026 |
| Redhat_linux | — | Upgrade tomcat9Upgrade tomcat9-servlet-4.0-apiUpgrade tomcat9-admin-webappsUpgrade tomcat9-libUpgrade tomcat9-webappsUpgrade tomcat9-jsp-2.3-apiUpgrade tomcat9-docs-webappUpgrade tomcat9-el-3.0-api | Jul 17, 2026 | Apr 9, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub