CVE-2026-59084
tomcat: Insufficient Technical Documentation (CVE-2026-59084)
Affected
- bitnami/tomcat
7.0.100..* - bitnami/tomcat
10.1.0..* - bitnami/tomcat
11.0.0..*
Description
A flaw was found in Apache Tomcat. Insufficient technical documentation regarding the secure configuration of the EncryptInterceptor component may lead to deployments with insecure settings. This vulnerability could allow an attacker to exploit misconfigurations that arise from unclear guidance, potentially compromising the confidentiality or integrity of data processed by the affected system.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
10.1.011.0.07.0.100Metrics
Show all metrics
Weakness classes (CWE)
CWE-1059Class
Insufficient Technical Documentation
The product does not contain sufficient technical or engineering documentation (whether on paper or in electronic form) that contains descriptions of all the relevant software/hardware elements of the product, such as its usage, structure, architectural components, interfaces, design, implementation, configuration, operation, etc.
cwe.mitre.org →