Metrics
Affected Vendors & Products
Tue, 14 Apr 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* |
Fri, 10 Apr 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-209 CWE-642 |
|
| Metrics |
ssvc
|
Fri, 10 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1240 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Fri, 10 Apr 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache tomcat |
|
| Vendors & Products |
Apache
Apache tomcat |
Fri, 10 Apr 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 09 Apr 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue. | |
| Title | Apache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-04-10T18:17:59.908Z
Reserved: 2026-03-04T10:35:55.231Z
Link: CVE-2026-29146
Updated: 2026-04-09T23:15:51.111Z
Status : Analyzed
Published: 2026-04-09T20:16:24.577
Modified: 2026-04-14T12:56:21.453
Link: CVE-2026-29146
OpenCVE Enrichment
Updated: 2026-04-14T16:36:51Z