PT-2026-53744 · Apache+1 · Apache Tomcat+1

·

CVE-2026-55955

·

Publicado

2026-06-22

·

Atualizado

2026-09-11

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Nome do Software Vulnerável e Versões Afetadas Apache Tomcat versões 11.0.0-M1 through 11.0.22 Apache Tomcat versões 10.1.0-M1 through 10.1.55 Apache Tomcat versões 9.0.13 through 9.0.18 Apache Tomcat versões 8.5.38 through 8.5.100 Apache Tomcat versões 7.0.100 through 7.0.109
Description Autenticação inadequada no componente de cluster permite um ataque de replay contra o EncryptionInterceptor. Um ataque de replay ocorre quando uma transmissão de dados válida é repetida ou atrasada de forma maliciosa ou fraudulenta.
Recommendations Atualizar versões 11.0.0-M1 through 11.0.22 para 11.0.23. Atualizar versões 10.1.0-M1 through 10.1.55 para 10.1.56. Atualizar versões 9.0.13 through 9.0.18 para 9.0.119. No momento, não há informações sobre uma versão mais recente que contenha a correção para esta vulnerabilidade nas versões 8.5.38 through 8.5.100 e 7.0.100 through 7.0.109.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-11871
BIT-TOMCAT-2026-55955
CVE-2026-55955
OESA-2026-2947
OESA-2026-2948
OESA-2026-2949
OESA-2026-2950
OPENSUSE-SU-2026:11195-1
OPENSUSE-SU-2026:11208-1
OPENSUSE-SU-2026:11209-1
OPENSUSE-SU-2026:21327-1
OPENSUSE-SU-2026:21328-1
OPENSUSE-SU-2026:21329-1
SUSE-SU-2026:22646-1
SUSE-SU-2026:22647-1
SUSE-SU-2026:22648-1
SUSE-SU-2026:3087-1
SUSE-SU-2026:3088-1
SUSE-SU-2026:3112-1
SUSE-SU-2026:3167-1

Produtos afetados

Apache Tomcat
Red Os