Skip to content
VulniPulse
Advisory severityLow3.8Red Hat Linux

Low [CVE-2026-59084] Insufficient documentation for EncryptInterceptor may lead to insecure configurations

This low-severity Red Hat Linux advisory covers CVE-2026-59084 affecting Red Hat Hardened Images, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-59084 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
Red Hat LinuxRed Hat Enterprise Linux
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109.

Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.

Insufficient technical documentation regarding the secure configuration of the EncryptInterceptor component may lead to deployments with insecure settings.

This vulnerability could allow an attacker to exploit misconfigurations that arise from unclear guidance, potentially compromising the confidentiality or integrity of data processed by the affected system.

Without clear guidance on secure configuration, administrators might inadvertently deploy the interceptor in a way that weakens security, rather than a direct code flaw. This issue affects Red Hat products utilizing Apache Tomcat, including Red Hat Enterprise Linux and Red Hat JBoss Web Server.

Red Hat severity: Low — CVSS 3.8 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N). Weakness: CWE-1188.

Red Hat lists Red Hat JBoss Web Server 6; Red Hat JBoss Web Server 7 as not affected.

Affected versions
  • 11.0.0
  • 11.0.23
  • 10.1.0
  • 10.1.56
  • 9.0.13
  • 9.0.119
  • 8.5.38
  • 8.5.100
  • 7.0.100
  • 7.0.109

Official advisory · high-confidence parse· fetched 11 days ago·verify at source

Fixed versions
  • 11.0.24
  • 10.1.57
  • 9.0.120
  • tomcat11-main-11.0.24-0.1.hum1
  • tomcat10-main-10.1.57-1.hum1
  • RHSA-2026:36872
  • RHSA-2026:37767

Official advisory · high-confidence parse· fetched 11 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • To mitigate this issue, ensure that the EncryptInterceptor in Apache Tomcat is configured according to secure best practices. Review existing configurations of EncryptInterceptor to verify that all security requirements are met and that no insecure settings are in place. If the EncryptInterceptor is not actively used, no specific action is required.

Official advisory · high-confidence parse· fetched 11 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.