セキュリティ

Apache Tomcat に10件の脆弱性

セキュリティ 元記事

予習

この記事のキーワード — タップで意味
×2
脆弱性
ぜいじゃくせい
vulnerability; weakness; fragility
×1
参照
さんしょう
reference; bibliographical reference; consultation; browsing (e.g. when selecting a file to upload on a computer); checking out
N1
×1
一般社団法人
いっぱんしゃだんほうじん
general incorporated association
×1
独立行政法人
どくりつぎょうせいほうじん
independent administrative corporation (institution, agency)
×1
下記
かき
the following
 独立行政法人情報処理推進機構(IPA)および一般社団法人JPCERT コーディネーションセンター(JPCERT/CC)は8月26日、Apache Tomcatにおける複数脆弱性について「Japan Vulnerability Notes(JVN)」で発表した。

 The Apache Software Foundationでは8月25日に、Apache Tomcatの10脆弱性に対してのアドバイザリを公開している。

 JVNでは、影響を受けるシステム、想定される影響対策方法については、下記のApache Tomcatのアドバイザリを参照するよう案内している。

[SECURITY] CVE-2026-65182 Apache Tomcat - Security constraint bypass

[SECURITY] CVE-2026-65183 Apache Tomcat - TOCTOU when setting specific permissions for Unix Domain Sockets

[SECURITY] CVE-2026-65637 Apache Tomcat - HTTP/2 no-authority bypass of strict SNI validation

[SECURITY] CVE-2026-65927 Apache Tomcat - RewriteValve [N] restarts at the second rule and may bypass access control

[SECURITY] CVE-2026-65905 Apache Tomcat - Limited replay attack possible with DIGEST authentication

[SECURITY] CVE-2026-66422 Apache Tomcat - Servlet role references can bypass declarative role constraints

[SECURITY] CVE-2026-68525 Apache Tomcat - Redirect after FORM authentication may bypass method specific constraints

[SECURITY] CVE-2026-73180 Apache Tomcat - Authenticated WebSocket session survives end of HTTP session

[SECURITY] CVE-2026-68569 Apache Tomcat - Principal lookup can fail open in some cases

[SECURITY] CVE-2026-68763 Apache Tomcat - DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset

この記事の単語 (15)

×2
脆弱性
ぜいじゃくせい
vulnerability; weakness; fragility
×2
影響
えいきょう
1. influence; effect 2. to influence; to affect; to have an influence on; to impact; to have an effect on
×1
独立行政法人
どくりつぎょうせいほうじん
independent administrative corporation (institution, agency)
×1
情報処理推進機構
じょうほうしょりすいしんきこう
Information-technology Promotion Agency (organization)
×1
及び
および
and; as well as
×1
一般社団法人
いっぱんしゃだんほうじん
general incorporated association
×1
複数
ふくすう
plural; multiple; several
×1
発表
はっぴょう
announcement; publication; presenting; statement; communique; making known; breaking (news story); expressing (one's opinion); releasing; unveiling
×1
けん
1. matter; affair; case; item; subject 2. counter for (received) emails, text messages, voicemail messages, etc.
×1
公開
こうかい
opening to the public; making available to the public; putting on display; exhibiting; showing (play, movie, etc.); holding (interview, etc.); open; public
×1
想定
そうてい
hypothesis; supposition; assumption
×1
対策
たいさく
measure; step; countermeasure; counterplan; countermove; strategy; preparation (e.g. for a test)
×1
方法
ほうほう
method; process; manner; way; means; technique
×1
下記
かき
the following
×1
参照
さんしょう
reference; bibliographical reference; consultation; browsing (e.g. when selecting a file to upload on a computer); checking out