セキュリティ

Apache Tomcat に複数の脆弱性

セキュリティ 元記事

予習

この記事のキーワード — タップで意味
×2
脆弱性
ぜいじゃくせい
vulnerability; weakness; fragility
×1
参照
さんしょう
reference; bibliographical reference; consultation; browsing (e.g. when selecting a file to upload on a computer); checking out
N1
×2
影響
えいきょう
1. influence; effect 2. to influence; to affect; to have an influence on; to impact; to have an effect on
×1
一般社団法人
いっぱんしゃだんほうじん
general incorporated association
×1
下記
かき
the following
 独立行政法人情報処理推進機構(IPA)および一般社団法人JPCERT コーディネーションセンター(JPCERT/CC)は7月1日、Apache Tomcatにおける複数脆弱性について「Japan Vulnerability Notes(JVN)」で発表した。

 The Apache Software Foundationでは6月29日に、Apache Tomcatの脆弱性(CVE-2026-55957、CVE-2026-55956、CVE-2026-55955、CVE-2026-55276、CVE-2026-53434、CVE-2026-53404、CVE-2026-50229)のアドバイザリを公開している。

 JVNでは、影響を受けるシステム、想定される影響対策方法については、下記のApache Tomcatのアドバイザリを参照するよう案内している。

[SECURITY] CVE-2026-55957 Apache Tomcat - Authentication bypass with JNDIRealm and GSSAPI authenticated bind-Apache Mail Archives

[SECURITY] CVE-2026-55956 Apache Tomcat - Security constraints for default servlet ignored method-Apache Mail Archives

[SECURITY] CVE-2026-55955 Apache Tomcat - EncryptInterceptor not protected against replay attacks-Apache Mail Archives

[SECURITY] CVE-2026-55276 Apache Tomcat - Logged effective web.xml is incomplete-Apache Mail Archives

[SECURITY] CVE-2026-53434 Apache Tomcat - Invalid CRL configuration doesn’t trigger failure for FFM Connector-Apache Mail Archives

[SECURITY] CVE-2026-53404 Apache Tomcat - Bad ornext processing in RewriteValve-Apache Mail Archives

[SECURITY] CVE-2026-50229 Apache Tomcat - XXS in number guess example-Apache Mail Archives

Apache Tomcat - Apache Tomcat 11 vulnerabilities

Apache Tomcat - Apache Tomcat 11 vulnerabilities

Apache Tomcat - Apache Tomcat 10 vulnerabilities

Apache Tomcat - Apache Tomcat 10 vulnerabilities

Apache Tomcat - Apache Tomcat 9 vulnerabilities

Apache Tomcat - Apache Tomcat 9 vulnerabilities

この記事の単語 (15)

×2
脆弱性
ぜいじゃくせい
vulnerability; weakness; fragility
×2
影響
えいきょう
1. influence; effect 2. to influence; to affect; to have an influence on; to impact; to have an effect on
×1
独立行政法人
どくりつぎょうせいほうじん
independent administrative corporation (institution, agency)
×1
情報処理推進機構
じょうほうしょりすいしんきこう
Information-technology Promotion Agency (organization)
×1
及び
および
and; as well as
×1
一般社団法人
いっぱんしゃだんほうじん
general incorporated association
×1
一日
ついたち
1. first day of the month 2. first ten days of the lunar month
×1
複数
ふくすう
plural; multiple; several
×1
発表
はっぴょう
announcement; publication; presenting; statement; communique; making known; breaking (news story); expressing (one's opinion); releasing; unveiling
×1
公開
こうかい
opening to the public; making available to the public; putting on display; exhibiting; showing (play, movie, etc.); holding (interview, etc.); open; public
×1
想定
そうてい
hypothesis; supposition; assumption
×1
対策
たいさく
measure; step; countermeasure; counterplan; countermove; strategy; preparation (e.g. for a test)
×1
方法
ほうほう
method; process; manner; way; means; technique
×1
下記
かき
the following
×1
参照
さんしょう
reference; bibliographical reference; consultation; browsing (e.g. when selecting a file to upload on a computer); checking out