Oval Definition:oval:org.opensuse.security:def:58272
Revision Date:2020-12-01Version:1
Title:Security update for tomcat (Important)
Description:

This update for tomcat fixes the following issues:

CVE-2020-9484 (bsc#1171928) Apache Tomcat Remote Code Execution via session persistence

If an attacker was able to control the contents and name of a file on a server configured to use the PersistenceManager, then the attacker could have triggered a remote code execution via deserialization of the file under their control.

CVE-2019-12418 (bsc#1159723) Local privilege escalation by manipulating the RMI registry and performing a man-in-the-middle attack

When Tomcat is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files was able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker could then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.

CVE-2019-0221 (bsc#1136085) The SSI printenv command echoed user provided data without escaping, which made it vulnerable to XSS.

CVE-2019-17563 (bsc#1159729) When using FORM authentication there was a narrow window where an attacker could perform a session fixation attack.

CVE-2019-17569 (bsc#1164825) Invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header.

Family:unixClass:patch
Status:Reference(s):1003581
1004003
1005084
1005090
1005242
1006591
1006593
1006597
1006598
1006599
1006836
1006839
1007009
1011044
1012060
1012382
1012422
1012452
1012829
1012910
1012985
1013561
1013887
1015342
1015452
1017461
1018885
1020412
1021424
1022266
1022595
1023287
1025461
1026570
1027101
1027512
1027519
1027974
1028217
1028310
1028340
1028883
1029607
1030057
1030070
1031040
1031142
1031147
1031470
1031500
1031512
1031555
1031717
1031796
1032141
1032339
1032345
1032400
1032581
1032803
1033117
1033281
1033336
1033340
1033885
1034048
1034419
1034635
1034670
1034671
1034762
1034849
1034902
1034995
1035024
1035866
1035887
1035920
1035922
1036214
1036638
1036752
1036763
1037177
1037186
1037384
1037483
1037669
1037840
1037871
1037969
1038033
1038043
1038085
1038142
1038143
1038297
1038458
1038544
1038842
1038843
1038846
1038847
1038848
1038879
1038981
1038982
1039214
1039348
1039354
1039700
1039864
1039882
1039883
1039885
1039900
1040069
1040125
1040182
1040279
1040351
1040364
1040395
1040425
1040463
1040567
1040609
1040855
1040929
1040941
1041087
1041160
1041168
1041242
1041431
1041810
1042286
1042356
1042421
1042517
1042535
1042536
1042863
1042886
1043014
1043231
1043236
1043347
1043371
1043467
1043488
1043598
1043912
1043935
1043990
1044015
1044082
1044120
1044125
1044532
1044767
1044772
1044854
1044880
1044912
1045154
1045235
1045286
1045307
1045467
1045568
1046105
1046434
1046589
1066295
1086039
1088268
1089152
1089635
1090036
1090820
1090822
1090823
1111331
1119947
1120943
1128481
1132728
1132729
1132732
1132734
1134718
1136085
1136570
1159723
1159729
1160467
1160468
1160770
1161799
1164825
1169740
1171355
1171928
1172651
1173334
1176410
1177143
392410
799133
863764
922871
939801
941919
942553
961886
963983
966170
966172
966191
966321
966339
968373
971975
988065
989311
990058
990682
993832
995542
CVE-2008-3522
CVE-2014-8158
CVE-2015-5203
CVE-2015-5221
CVE-2016-1577
CVE-2016-1867
CVE-2016-2089
CVE-2016-2116
CVE-2016-8690
CVE-2016-8691
CVE-2016-8692
CVE-2016-8693
CVE-2016-8880
CVE-2016-8881
CVE-2016-8882
CVE-2016-8883
CVE-2016-8884
CVE-2016-8885
CVE-2016-8886
CVE-2016-8887
CVE-2017-0861
CVE-2017-1000365
CVE-2017-1000380
CVE-2017-13080
CVE-2017-13081
CVE-2017-3509
CVE-2017-3511
CVE-2017-3512
CVE-2017-3514
CVE-2017-3526
CVE-2017-3533
CVE-2017-3539
CVE-2017-3544
CVE-2017-5754
CVE-2017-7346
CVE-2017-7487
CVE-2017-7616
CVE-2017-7618
CVE-2017-8890
CVE-2017-8924
CVE-2017-8925
CVE-2017-9074
CVE-2017-9075
CVE-2017-9076
CVE-2017-9077
CVE-2017-9150
CVE-2017-9242
CVE-2018-1000199
CVE-2018-10471
CVE-2018-10472
CVE-2018-12126
CVE-2018-12127
CVE-2018-12130
CVE-2018-16884
CVE-2018-20030
CVE-2018-8897
CVE-2018-8956
CVE-2019-0221
CVE-2019-10245
CVE-2019-11091
CVE-2019-12418
CVE-2019-14896
CVE-2019-14897
CVE-2019-17563
CVE-2019-17569
CVE-2019-2602
CVE-2019-2684
CVE-2019-2697
CVE-2019-2698
CVE-2019-3860
CVE-2019-9278
CVE-2020-11868
CVE-2020-13817
CVE-2020-15025
CVE-2020-25219
CVE-2020-26154
CVE-2020-6796
CVE-2020-6797
CVE-2020-6798
CVE-2020-6799
CVE-2020-6800
CVE-2020-9484
SUSE-SU-2016:2775-1
SUSE-SU-2017:1445-1
SUSE-SU-2017:1853-1
SUSE-SU-2017:3106-1
SUSE-SU-2018:1241-1
SUSE-SU-2018:3230-1
SUSE-SU-2019:0356-1
SUSE-SU-2020:0384-1
SUSE-SU-2020:0457-1
SUSE-SU-2020:1498-1
SUSE-SU-2020:1805-1
SUSE-SU-2020:2900-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.1
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE OpenStack Cloud 7
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud Crowbar 8
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND Package Information
  • cracklib-2.9.6-lp150.2 is installed
  • OR libcrack2-2.9.6-lp150.2 is installed
  • OR libcrack2-32bit-2.9.6-lp150.2 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • exim-4.88-lp151.4.3 is installed
  • OR eximon-4.88-lp151.4.3 is installed
  • OR eximstats-html-4.88-lp151.4.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND Package Information
  • jasper-1.900.14-181 is installed
  • OR libjasper1-1.900.14-181 is installed
  • OR libjasper1-32bit-1.900.14-181 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND Package Information
  • xen-4.7.5_02-43.30 is installed
  • OR xen-doc-html-4.7.5_02-43.30 is installed
  • OR xen-libs-4.7.5_02-43.30 is installed
  • OR xen-libs-32bit-4.7.5_02-43.30 is installed
  • OR xen-tools-4.7.5_02-43.30 is installed
  • OR xen-tools-domU-4.7.5_02-43.30 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND ucode-intel-20190514-13.44 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND Package Information
  • kgraft-patch-4_4_90-92_50-default-6-2 is installed
  • OR kgraft-patch-SLE12-SP2_Update_15-6-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND autofs-5.0.9-27 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND Package Information
  • libsqlite3-0-3.8.10.2-9.15 is installed
  • OR libsqlite3-0-32bit-3.8.10.2-9.15 is installed
  • OR sqlite3-3.8.10.2-9.15 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND Package Information
  • ceph-12.2.13+git.1592168685.85110a3e9d-2.50 is installed
  • OR ceph-common-12.2.13+git.1592168685.85110a3e9d-2.50 is installed
  • OR libcephfs2-12.2.13+git.1592168685.85110a3e9d-2.50 is installed
  • OR librados2-12.2.13+git.1592168685.85110a3e9d-2.50 is installed
  • OR libradosstriper1-12.2.13+git.1592168685.85110a3e9d-2.50 is installed
  • OR librbd1-12.2.13+git.1592168685.85110a3e9d-2.50 is installed
  • OR librgw2-12.2.13+git.1592168685.85110a3e9d-2.50 is installed
  • OR python-cephfs-12.2.13+git.1592168685.85110a3e9d-2.50 is installed
  • OR python-rados-12.2.13+git.1592168685.85110a3e9d-2.50 is installed
  • OR python-rbd-12.2.13+git.1592168685.85110a3e9d-2.50 is installed
  • OR python-rgw-12.2.13+git.1592168685.85110a3e9d-2.50 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • libpolkit0-0.113-5.18 is installed
  • OR polkit-0.113-5.18 is installed
  • OR typelib-1_0-Polkit-1_0-0.113-5.18 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • gdm-3.10.0.1-54.6 is installed
  • OR gdm-lang-3.10.0.1-54.6 is installed
  • OR gdmflexiserver-3.10.0.1-54.6 is installed
  • OR libgdm1-3.10.0.1-54.6 is installed
  • OR typelib-1_0-Gdm-1_0-3.10.0.1-54.6 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND libdmx1-1.1.3-3 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND Package Information
  • tomcat-8.0.53-29.27 is installed
  • OR tomcat-admin-webapps-8.0.53-29.27 is installed
  • OR tomcat-docs-webapp-8.0.53-29.27 is installed
  • OR tomcat-el-3_0-api-8.0.53-29.27 is installed
  • OR tomcat-javadoc-8.0.53-29.27 is installed
  • OR tomcat-jsp-2_3-api-8.0.53-29.27 is installed
  • OR tomcat-lib-8.0.53-29.27 is installed
  • OR tomcat-servlet-3_1-api-8.0.53-29.27 is installed
  • OR tomcat-webapps-8.0.53-29.27 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND Package Information
  • MozillaFirefox-68.2.0-109.95 is installed
  • OR MozillaFirefox-translations-common-68.2.0-109.95 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND Package Information
  • ruby2.1-rubygem-sprockets-2_12-2.12.5-1.4 is installed
  • OR rubygem-sprockets-2_12-2.12.5-1.4 is installed
  • BACK