Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
This update includes the following RPMs: tomcat11: * tomcat11-11.0.23-0.1.hum1 (noarch) * tomcat11-admin-webapps-11.0.23-0.1.hum1 (noarch) * tomcat11-common-11.0.23-0.1.hum1 (noarch) * tomcat11-docs-webapp-11.0.23-0.1.hum1 (noarch) * tomcat11-el-6.0-api-11.0.23-0.1.hum1 (noarch) * tomcat11-jsp-4.0-api-11.0.23-0.1.hum1 (noarch) * tomcat11-lib-11.0.23-0.1.hum1 (noarch) * tomcat11-servlet-6.1-api-11.0.23-0.1.hum1 (noarch) * tomcat11-user-instance-11.0.23-0.1.hum1 (noarch) * tomcat11-webapps-11.0.23-0.1.hum1 (noarch) * tomcat11-11.0.23-0.1.hum1.src (src)
AI Analysis
Technical Summary
The advisory updates multiple tomcat11 RPM packages in Red Hat Hardened Images to address several security vulnerabilities, including CVE-2026-55955, which is an improper authentication vulnerability in Apache Tomcat's EncryptionInterceptor component used for Tribes cluster communication. This flaw allows a remote attacker to perform a replay attack on encrypted cluster messages, potentially leading to unauthorized access or data manipulation within the cluster. Exploitation requires the EncryptionInterceptor to be configured (a non-default setting) and attacker access to the cluster network. Red Hat has adjusted the severity of this vulnerability to moderate (CVSS 3.1 vector: AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N) due to the limited attack surface. The advisory includes updates to tomcat11 packages at version 11.0.23-0.1.hum1 (noarch) and related components. No explicit patch links were provided, but the advisory references updated RPMs available via Red Hat's repositories.
Potential Impact
The vulnerabilities addressed could allow unauthorized access or manipulation of data within Tomcat clusters if the EncryptionInterceptor is used for Tribes cluster communication. Since this configuration is non-default and requires attacker access to the cluster network, the overall impact is limited to specific deployment scenarios. Other included CVEs address various security issues in the tomcat11 RPMs. The advisory rates the overall severity as critical, but the specific EncryptionInterceptor vulnerability is considered moderate by Red Hat. There are no known exploits in the wild at this time.
Mitigation Recommendations
Red Hat has released updated tomcat11 RPM packages (version 11.0.23-0.1.hum1) that include fixes for the described vulnerabilities. Users should apply these updates to affected Red Hat Hardened Images to remediate the issues. For the EncryptionInterceptor vulnerability, mitigation includes ensuring that cluster communication channels are restricted to trusted, isolated networks and avoiding use of the EncryptionInterceptor unless necessary. Deployments not using Tomcat clustering or not configuring the EncryptionInterceptor are not affected. Since this is an RPM update, applying the vendor-provided packages is the recommended remediation.
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Description
This update includes the following RPMs: tomcat11: * tomcat11-11.0.23-0.1.hum1 (noarch) * tomcat11-admin-webapps-11.0.23-0.1.hum1 (noarch) * tomcat11-common-11.0.23-0.1.hum1 (noarch) * tomcat11-docs-webapp-11.0.23-0.1.hum1 (noarch) * tomcat11-el-6.0-api-11.0.23-0.1.hum1 (noarch) * tomcat11-jsp-4.0-api-11.0.23-0.1.hum1 (noarch) * tomcat11-lib-11.0.23-0.1.hum1 (noarch) * tomcat11-servlet-6.1-api-11.0.23-0.1.hum1 (noarch) * tomcat11-user-instance-11.0.23-0.1.hum1 (noarch) * tomcat11-webapps-11.0.23-0.1.hum1 (noarch) * tomcat11-11.0.23-0.1.hum1.src (src)
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The advisory updates multiple tomcat11 RPM packages in Red Hat Hardened Images to address several security vulnerabilities, including CVE-2026-55955, which is an improper authentication vulnerability in Apache Tomcat's EncryptionInterceptor component used for Tribes cluster communication. This flaw allows a remote attacker to perform a replay attack on encrypted cluster messages, potentially leading to unauthorized access or data manipulation within the cluster. Exploitation requires the EncryptionInterceptor to be configured (a non-default setting) and attacker access to the cluster network. Red Hat has adjusted the severity of this vulnerability to moderate (CVSS 3.1 vector: AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N) due to the limited attack surface. The advisory includes updates to tomcat11 packages at version 11.0.23-0.1.hum1 (noarch) and related components. No explicit patch links were provided, but the advisory references updated RPMs available via Red Hat's repositories.
Potential Impact
The vulnerabilities addressed could allow unauthorized access or manipulation of data within Tomcat clusters if the EncryptionInterceptor is used for Tribes cluster communication. Since this configuration is non-default and requires attacker access to the cluster network, the overall impact is limited to specific deployment scenarios. Other included CVEs address various security issues in the tomcat11 RPMs. The advisory rates the overall severity as critical, but the specific EncryptionInterceptor vulnerability is considered moderate by Red Hat. There are no known exploits in the wild at this time.
Mitigation Recommendations
Red Hat has released updated tomcat11 RPM packages (version 11.0.23-0.1.hum1) that include fixes for the described vulnerabilities. Users should apply these updates to affected Red Hat Hardened Images to remediate the issues. For the EncryptionInterceptor vulnerability, mitigation includes ensuring that cluster communication channels are restricted to trusted, isolated networks and avoiding use of the EncryptionInterceptor unless necessary. Deployments not using Tomcat clustering or not configuring the EncryptionInterceptor are not affected. Since this is an RPM update, applying the vendor-provided packages is the recommended remediation.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:32960
- Cve Count
- 5
- Additional Cves
- ["CVE-2026-53404","CVE-2026-53434","CVE-2026-55276","CVE-2026-55955"]
- Cvss Version
- 3.1
Threat ID: 6a44530127e9c79719916bc3
Added to database: 06/30/2026, 23:36:33 UTC
Last enriched: 08/09/2026, 16:01:31 UTC
Last updated: 08/14/2026, 12:41:10 UTC
Views: 156
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.