Impact
The vulnerability is a documentation issue where the requirements to securely configure the EncryptInterceptor are not clearly documented. The weakness is classified as CWE‑1059. Based on the description, if an administrator assumes the default settings are sufficient, the interceptor may be left in an insecure state, potentially allowing an attacker to intercept, read, or tamper with data transmitted between client and server.
Affected Systems
The flaw affects Apache Tomcat releases from 11.0.0‑M1 to 11.0.23, from 10.1.0‑M1 to 10.1.56, from 9.0.13 to 9.0.119, from 8.5.38 to 8.5.100, and from 7.0.100 to 7.0.109. Any other Tomcat versions that have reached end of support may also suffer from the same lack of documentation. All affected releases are distributed by the Apache Software Foundation.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity due to potential impact on confidentiality. The EPSS score of <1% shows that exploitation is not widely observed, but the flaw can be abused by anyone who can edit configuration files. Based on the description, the likely attack vector is an entity with configuration or administrative privilege on the Tomcat server that intentionally or mistakenly alters the EncryptInterceptor settings. Since the vulnerability stems from documentation, it is not currently listed in CISA’s KEV catalog.
OpenCVE Enrichment