Apache Software Foundation Apache Tomcat, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support 취약점
CVE-2026-29146(cve-2026-29146)에 대한 수정으로 인해 Apache Tomcat에 민감한 데이터의 암호화 누락 취약점이 발생하며, 이를 통해 EncryptInterceptor를 우회할 수 있습니다. 이 문제는 Apache Tomcat 11.0.20, 10.1.53, 9.0.116에 영향을 미칩니다. 사용자는 이 문제를 수정한 version 11.0.21, 10.1.54 또는 9.0.117로 업그레이드할 것을 권고받습니다.
CVE-2026-29146(cve-2026-29146)에 대한 수정으로 인해 Apache Tomcat에 민감한 데이터의 암호화 누락 취약점이 발생하며, 이를 통해 EncryptInterceptor를 우회할 수 있습니다. 이 문제는 Apache Tomcat 11.0.20, 10.1.53, 9.0.116에 영향을 미칩니다. 사용자는 이 문제를 수정한 version 11.0.21, 10.1.54 또는 9.0.117로 업그레이드할 것을 권고받습니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
영향 제품·버전
제품 Apache Software Foundation Apache Tomcat, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support
영향 버전 Apache Software Foundation Apache Tomcat, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support >= 11.0.20, >= 10.1.53, >= 9.0.116, 9.0.116, 10.1.53, 11.0.20, 7.0.0, 8.0, 9.0, 10.0, 7.0, 8.8, 9.2, 9.4, 9.6
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
조치 기한: 2026.08.07
해당사항 확인방법
Apache Software Foundation Apache Tomcat, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support의 현재 전체 버전이 공식 영향 범위(Apache Software Foundation Apache Tomcat, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support >= 11.0.20, >= 10.1.53, >= 9.0.116, 9.0.116, 10.1.53, 11.0.20, 7.0.0, 8.0, 9.0, 10.0, 7.0, 8.8, 9.2, 9.4, 9.6)에 포함되는지 확인합니다. OS를 선택하면 해당 OS의 제품·패키지·KB·APAR 확인 명령만 표시됩니다.
조치방안
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
조치 후 확인사항
패치 후 같은 명령으로 전체 버전을 다시 확인해 수정 버전은 공급사 공식자료 확인 필요 기준을 충족하는지 확인합니다. 이어서 암호화·인증서 취약점 관련 오류·공격 흔적이 새로 발생하지 않는지 확인합니다.