tomcat-9.0.117-2.el9_8
エラータID: AXSA:2026-1478:06
Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies.
Security Fix(es):
* Apache Tomcat: Apache Tomcat: Information disclosure via Padding Oracle vulnerability in EncryptInterceptor (CVE-2026-29146)
* Apache Tomcat: Apache Tomcat: Missing Encryption of Sensitive Data due to EncryptInterceptor bypass (CVE-2026-34486)
Bug Fix(es) and Enhancement(s):
* Remove tomcat clustering JAR from RPM builds (JIRA:RHEL-183992)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-29146
Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.
CVE-2026-34486
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
Update packages.
Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
N/A
SRPMS
- tomcat-9.0.117-2.el9_8.src.rpm
MD5: f8bc90880eae1c86370bcb7bcdf53a89
SHA-256: 9557143e03bcbf7cbedb45c1a8df392244dab775cdd4df3540377a3c9fe1fd4e
Size: 7.16 MB
Asianux Server 9 for x86_64
- tomcat-9.0.117-2.el9_8.noarch.rpm
MD5: 40fd8d2efaa34e0bc33bb7326a05167a
SHA-256: 3a3ab7314bbf36eba40e229dd3543e0334333a01025bc021e248244c34c6dd88
Size: 99.87 kB - tomcat-admin-webapps-9.0.117-2.el9_8.noarch.rpm
MD5: 5d94c1856616505afe98b78cafc595aa
SHA-256: 269b669f04f494f48112472b8764ad9b63b4167c1a7fad9150d2501febb7974e
Size: 85.18 kB - tomcat-docs-webapp-9.0.117-2.el9_8.noarch.rpm
MD5: 24f118fe2fadacca6d80a0b22bef6c5d
SHA-256: 554a66726a36c23f54e3b8f43b6aa608606935beae12eae3ee1cf3b8c51efd0d
Size: 1.52 MB - tomcat-el-3.0-api-9.0.117-2.el9_8.noarch.rpm
MD5: adcf276220d159ed1625351abfcd709b
SHA-256: 46aeafbf3354ca219e1e249ea7623b84ca55f0c630a36cb490f3222f6e664d66
Size: 106.02 kB - tomcat-jsp-2.3-api-9.0.117-2.el9_8.noarch.rpm
MD5: eb16228d26dee9a0aa285ab7bc9b873e
SHA-256: 5706b7c9b123f755d08e864291b1e84a343f22bccc40dc5a78cbfd6ddea8340a
Size: 73.90 kB - tomcat-lib-9.0.117-2.el9_8.noarch.rpm
MD5: 4e611a346597c9631ca628e39eb7800c
SHA-256: 06db83da9e0f714126e824dc6c4abca364c0ad423520da4bbdecdc3383fb41a2
Size: 6.04 MB - tomcat-servlet-4.0-api-9.0.117-2.el9_8.noarch.rpm
MD5: 5877b49469042308f71b008a395cf670
SHA-256: d02c27d30685008e5e337b87f3eb4c41484a304d6f044f848f4ed5bb5041802b
Size: 285.51 kB - tomcat-webapps-9.0.117-2.el9_8.noarch.rpm
MD5: c44c44dda5109417bf85ef2db27f5add
SHA-256: 94665ea7d9d8c3bd9c6015f95d188a069f7eff3fea00a826416eba2bc97f0700
Size: 76.93 kB