Oval Definition:oval:com.redhat.rhsa:def:20162599
Revision Date:2016-11-03Version:646
Title:RHSA-2016:2599: tomcat security, bug fix, and enhancement update (Moderate)
Description:Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies.

  • The following packages have been upgraded to a newer upstream version: tomcat (7.0.69). (BZ#1287928)

    Security Fix(es):

  • A CSRF flaw was found in Tomcat's the index pages for the Manager and Host Manager applications. These applications included a valid CSRF token when issuing a redirect as a result of an unauthenticated request to the root of the web application. This token could then be used by an attacker to perform a CSRF attack. (CVE-2015-5351)

  • It was found that several Tomcat session persistence mechanisms could allow a remote, authenticated user to bypass intended SecurityManager restrictions and execute arbitrary code in a privileged context via a web application that placed a crafted object in a session. (CVE-2016-0714)

  • A security manager bypass flaw was found in Tomcat that could allow remote, authenticated users to access arbitrary application data, potentially resulting in a denial of service. (CVE-2016-0763)

  • A denial of service vulnerability was identified in Commons FileUpload that occurred when the length of the multipart boundary was just below the size of the buffer (4096 bytes) used to read the uploaded file if the boundary was the typical tens of bytes long. (CVE-2016-3092)

  • A directory traversal flaw was found in Tomcat's RequestUtil.java. A remote, authenticated user could use this flaw to bypass intended SecurityManager restrictions and list a parent directory via a '/..' in a pathname used by a web application in a getResource, getResourceAsStream, or getResourcePaths call. (CVE-2015-5174)

  • It was found that Tomcat could reveal the presence of a directory even when that directory was protected by a security constraint. A user could make a request to a directory via a URL not ending with a slash and, depending on whether Tomcat redirected that request, could confirm whether that directory existed. (CVE-2015-5345)

  • It was found that Tomcat allowed the StatusManagerServlet to be loaded by a web application when a security manager was configured. This allowed a web application to list all deployed web applications and expose sensitive information such as session IDs. (CVE-2016-0706)

    Additional Changes:

    For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.3 Release Notes linked from the References section.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2014-0230
    CVE-2015-5174
    CVE-2015-5345
    CVE-2015-5351
    CVE-2016-0706
    CVE-2016-0714
    CVE-2016-0763
    CVE-2016-3092
    RHSA-2016:2599
    RHSA-2016:2599-01
    RHSA-2016:2599-02
    RHSA-2016:2599-02
    Platform(s):Red Hat Enterprise Linux 7
    Red Hat Enterprise Linux 7 (please do not use for >= RHEL-7.5)
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • tomcat is earlier than 0:7.0.69-10.el7
  • AND tomcat is signed with Red Hat redhatrelease2 key
  • tomcat-admin-webapps is earlier than 0:7.0.69-10.el7
  • AND tomcat-admin-webapps is signed with Red Hat redhatrelease2 key
  • tomcat-docs-webapp is earlier than 0:7.0.69-10.el7
  • AND tomcat-docs-webapp is signed with Red Hat redhatrelease2 key
  • tomcat-el-2.2-api is earlier than 0:7.0.69-10.el7
  • AND tomcat-el-2.2-api is signed with Red Hat redhatrelease2 key
  • tomcat-javadoc is earlier than 0:7.0.69-10.el7
  • AND tomcat-javadoc is signed with Red Hat redhatrelease2 key
  • tomcat-jsp-2.2-api is earlier than 0:7.0.69-10.el7
  • AND tomcat-jsp-2.2-api is signed with Red Hat redhatrelease2 key
  • tomcat-jsvc is earlier than 0:7.0.69-10.el7
  • AND tomcat-jsvc is signed with Red Hat redhatrelease2 key
  • tomcat-lib is earlier than 0:7.0.69-10.el7
  • AND tomcat-lib is signed with Red Hat redhatrelease2 key
  • tomcat-servlet-3.0-api is earlier than 0:7.0.69-10.el7
  • AND tomcat-servlet-3.0-api is signed with Red Hat redhatrelease2 key
  • tomcat-webapps is earlier than 0:7.0.69-10.el7
  • AND tomcat-webapps is signed with Red Hat redhatrelease2 key
  • Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 7 Client is installed
  • OR Red Hat Enterprise Linux 7 Server is installed
  • OR Red Hat Enterprise Linux 7 Workstation is installed
  • OR Red Hat Enterprise Linux 7 ComputeNode is installed
  • AND Package Information
  • tomcat-el-2.2-api is earlier than 0:7.0.69-10.el7
  • AND tomcat-el-2.2-api is signed with Red Hat redhatrelease2 key
  • OR
  • tomcat-docs-webapp is earlier than 0:7.0.69-10.el7
  • AND tomcat-docs-webapp is signed with Red Hat redhatrelease2 key
  • OR
  • tomcat-lib is earlier than 0:7.0.69-10.el7
  • AND tomcat-lib is signed with Red Hat redhatrelease2 key
  • OR
  • tomcat-admin-webapps is earlier than 0:7.0.69-10.el7
  • AND tomcat-admin-webapps is signed with Red Hat redhatrelease2 key
  • OR
  • tomcat is earlier than 0:7.0.69-10.el7
  • AND tomcat is signed with Red Hat redhatrelease2 key
  • OR
  • tomcat-jsp-2.2-api is earlier than 0:7.0.69-10.el7
  • AND tomcat-jsp-2.2-api is signed with Red Hat redhatrelease2 key
  • OR
  • tomcat-webapps is earlier than 0:7.0.69-10.el7
  • AND tomcat-webapps is signed with Red Hat redhatrelease2 key
  • OR
  • tomcat-jsvc is earlier than 0:7.0.69-10.el7
  • AND tomcat-jsvc is signed with Red Hat redhatrelease2 key
  • OR
  • tomcat-javadoc is earlier than 0:7.0.69-10.el7
  • AND tomcat-javadoc is signed with Red Hat redhatrelease2 key
  • OR
  • tomcat-servlet-3.0-api is earlier than 0:7.0.69-10.el7
  • AND tomcat-servlet-3.0-api is signed with Red Hat redhatrelease2 key
  • BACK