Oval Definition:oval:com.redhat.rhsa:def:20173081
Revision Date:2017-10-30Version:638
Title:RHSA-2017:3081: tomcat security update (Important)
Description:Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies.

Security Fix(es):

  • A vulnerability was discovered in Tomcat's handling of pipelined requests when "Sendfile" was used. If sendfile processing completed quickly, it was possible for the Processor to be added to the processor cache twice. This could lead to invalid responses or information disclosure. (CVE-2017-5647)

  • Two vulnerabilities were discovered in Tomcat where if a servlet context was configured with readonly=false and HTTP PUT requests were allowed, an attacker could upload a JSP file to that context and achieve code execution. (CVE-2017-12615, CVE-2017-12617)

  • A vulnerability was discovered in Tomcat where the CORS Filter did not send a "Vary: Origin" HTTP header. This potentially allowed sensitive data to be leaked to other visitors through both client-side and server-side caches. (CVE-2017-7674)
  • Family:unixClass:patch
    Status:Reference(s):CVE-2017-12615
    CVE-2017-12617
    CVE-2017-5647
    CVE-2017-7674
    RHSA-2017:3081
    RHSA-2017:3081-00
    RHSA-2017:3081-01
    Platform(s):Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • tomcat is earlier than 0:7.0.76-3.el7_4
  • AND tomcat is signed with Red Hat redhatrelease2 key
  • tomcat-admin-webapps is earlier than 0:7.0.76-3.el7_4
  • AND tomcat-admin-webapps is signed with Red Hat redhatrelease2 key
  • tomcat-docs-webapp is earlier than 0:7.0.76-3.el7_4
  • AND tomcat-docs-webapp is signed with Red Hat redhatrelease2 key
  • tomcat-el-2.2-api is earlier than 0:7.0.76-3.el7_4
  • AND tomcat-el-2.2-api is signed with Red Hat redhatrelease2 key
  • tomcat-javadoc is earlier than 0:7.0.76-3.el7_4
  • AND tomcat-javadoc is signed with Red Hat redhatrelease2 key
  • tomcat-jsp-2.2-api is earlier than 0:7.0.76-3.el7_4
  • AND tomcat-jsp-2.2-api is signed with Red Hat redhatrelease2 key
  • tomcat-jsvc is earlier than 0:7.0.76-3.el7_4
  • AND tomcat-jsvc is signed with Red Hat redhatrelease2 key
  • tomcat-lib is earlier than 0:7.0.76-3.el7_4
  • AND tomcat-lib is signed with Red Hat redhatrelease2 key
  • tomcat-servlet-3.0-api is earlier than 0:7.0.76-3.el7_4
  • AND tomcat-servlet-3.0-api is signed with Red Hat redhatrelease2 key
  • tomcat-webapps is earlier than 0:7.0.76-3.el7_4
  • AND tomcat-webapps is signed with Red Hat redhatrelease2 key
  • BACK