Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.
Webサーバーの脆弱性は、自社のWebサイトや社内システムへの不正アクセス・改ざんにつながります。外部委託しているWebサイトも対象となる可能性があります。