Oval Definition:oval:org.opensuse.security:def:60694
Revision Date:2020-12-01Version:1
Title:Security update for tomcat (Important)
Description:

This update for tomcat fixes the following issues:

CVE-2020-9484 (bsc#1171928) Apache Tomcat Remote Code Execution via session persistence

If an attacker was able to control the contents and name of a file on a server configured to use the PersistenceManager, then the attacker could have triggered a remote code execution via deserialization of the file under their control.

CVE-2019-12418 (bsc#1159723) Local privilege escalation by manipulating the RMI registry and performing a man-in-the-middle attack

When Tomcat is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files was able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker could then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.

CVE-2019-0221 (bsc#1136085) The SSI printenv command echoed user provided data without escaping, which made it vulnerable to XSS.

CVE-2019-17563 (bsc#1159729) When using FORM authentication there was a narrow window where an attacker could perform a session fixation attack.

CVE-2019-17569 (bsc#1164825) Invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header.

Family:unixClass:patch
Status:Reference(s):1052829
1056450
1082828
1101820
1106171
1106172
1106173
1106195
1107410
1107411
1107412
1107413
1107420
1107421
1107422
1107423
1107426
1107581
1108027
1108752
1108756
1108757
1108761
1108762
1109105
1111151
1120531
1122012
1136085
1144504
1149458
1151839
1154824
1156353
1159723
1159729
1159819
1160968
1162610
1164825
1168669
1169511
1169746
1170908
1171352
1171928
1171978
1172277
1172466
1173022
1176421
1176496
1176764
936786
976955
CVE-2013-7490
CVE-2015-3239
CVE-2017-14062
CVE-2017-15130
CVE-2017-7753
CVE-2017-7779
CVE-2017-7782
CVE-2017-7784
CVE-2017-7785
CVE-2017-7786
CVE-2017-7787
CVE-2017-7791
CVE-2017-7792
CVE-2017-7798
CVE-2017-7800
CVE-2017-7801
CVE-2017-7802
CVE-2017-7803
CVE-2017-7804
CVE-2017-7807
CVE-2018-1000805
CVE-2018-10903
CVE-2018-15908
CVE-2018-15909
CVE-2018-15910
CVE-2018-15911
CVE-2018-16509
CVE-2018-16510
CVE-2018-16511
CVE-2018-16513
CVE-2018-16539
CVE-2018-16540
CVE-2018-16541
CVE-2018-16542
CVE-2018-16543
CVE-2018-16585
CVE-2018-16741
CVE-2018-16742
CVE-2018-16743
CVE-2018-16744
CVE-2018-16745
CVE-2018-16802
CVE-2018-17183
CVE-2019-0221
CVE-2019-12418
CVE-2019-12625
CVE-2019-12900
CVE-2019-17006
CVE-2019-17563
CVE-2019-17569
CVE-2019-20919
CVE-2019-2949
CVE-2020-0543
CVE-2020-0548
CVE-2020-0549
CVE-2020-12399
CVE-2020-12402
CVE-2020-15169
CVE-2020-2654
CVE-2020-2754
CVE-2020-2755
CVE-2020-2756
CVE-2020-2757
CVE-2020-2781
CVE-2020-2800
CVE-2020-2803
CVE-2020-2805
CVE-2020-2830
CVE-2020-8597
CVE-2020-9484
SUSE-SU-2017:2589-1
SUSE-SU-2018:0878-1
SUSE-SU-2018:3553-1
SUSE-SU-2019:0284-1
SUSE-SU-2019:0396-1
SUSE-SU-2019:3066-1
SUSE-SU-2020:0490-1
SUSE-SU-2020:1498-1
SUSE-SU-2020:1685-1
SUSE-SU-2020:1839-1
SUSE-SU-2020:2686-1
SUSE-SU-2020:2856-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.1
openSUSE Leap 15.2
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud 9
SUSE OpenStack Cloud Crowbar 8
SUSE OpenStack Cloud Crowbar 9
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND Package Information
  • g3utils-1.1.37-lp150.2.3 is installed
  • OR mgetty-1.1.37-lp150.2.3 is installed
  • OR sendfax-1.1.37-lp150.2.3 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • apache2-mod_php7-7.2.5-lp151.6.6 is installed
  • OR php7-7.2.5-lp151.6.6 is installed
  • OR php7-bcmath-7.2.5-lp151.6.6 is installed
  • OR php7-bz2-7.2.5-lp151.6.6 is installed
  • OR php7-calendar-7.2.5-lp151.6.6 is installed
  • OR php7-ctype-7.2.5-lp151.6.6 is installed
  • OR php7-curl-7.2.5-lp151.6.6 is installed
  • OR php7-dba-7.2.5-lp151.6.6 is installed
  • OR php7-devel-7.2.5-lp151.6.6 is installed
  • OR php7-dom-7.2.5-lp151.6.6 is installed
  • OR php7-embed-7.2.5-lp151.6.6 is installed
  • OR php7-enchant-7.2.5-lp151.6.6 is installed
  • OR php7-exif-7.2.5-lp151.6.6 is installed
  • OR php7-fastcgi-7.2.5-lp151.6.6 is installed
  • OR php7-fileinfo-7.2.5-lp151.6.6 is installed
  • OR php7-firebird-7.2.5-lp151.6.6 is installed
  • OR php7-fpm-7.2.5-lp151.6.6 is installed
  • OR php7-ftp-7.2.5-lp151.6.6 is installed
  • OR php7-gd-7.2.5-lp151.6.6 is installed
  • OR php7-gettext-7.2.5-lp151.6.6 is installed
  • OR php7-gmp-7.2.5-lp151.6.6 is installed
  • OR php7-iconv-7.2.5-lp151.6.6 is installed
  • OR php7-intl-7.2.5-lp151.6.6 is installed
  • OR php7-json-7.2.5-lp151.6.6 is installed
  • OR php7-ldap-7.2.5-lp151.6.6 is installed
  • OR php7-mbstring-7.2.5-lp151.6.6 is installed
  • OR php7-mysql-7.2.5-lp151.6.6 is installed
  • OR php7-odbc-7.2.5-lp151.6.6 is installed
  • OR php7-opcache-7.2.5-lp151.6.6 is installed
  • OR php7-openssl-7.2.5-lp151.6.6 is installed
  • OR php7-pcntl-7.2.5-lp151.6.6 is installed
  • OR php7-pdo-7.2.5-lp151.6.6 is installed
  • OR php7-pear-7.2.5-lp151.6.6 is installed
  • OR php7-pear-Archive_Tar-7.2.5-lp151.6.6 is installed
  • OR php7-pgsql-7.2.5-lp151.6.6 is installed
  • OR php7-phar-7.2.5-lp151.6.6 is installed
  • OR php7-posix-7.2.5-lp151.6.6 is installed
  • OR php7-readline-7.2.5-lp151.6.6 is installed
  • OR php7-shmop-7.2.5-lp151.6.6 is installed
  • OR php7-snmp-7.2.5-lp151.6.6 is installed
  • OR php7-soap-7.2.5-lp151.6.6 is installed
  • OR php7-sockets-7.2.5-lp151.6.6 is installed
  • OR php7-sodium-7.2.5-lp151.6.6 is installed
  • OR php7-sqlite-7.2.5-lp151.6.6 is installed
  • OR php7-sysvmsg-7.2.5-lp151.6.6 is installed
  • OR php7-sysvsem-7.2.5-lp151.6.6 is installed
  • OR php7-sysvshm-7.2.5-lp151.6.6 is installed
  • OR php7-testresults-7.2.5-lp151.6.6 is installed
  • OR php7-tidy-7.2.5-lp151.6.6 is installed
  • OR php7-tokenizer-7.2.5-lp151.6.6 is installed
  • OR php7-wddx-7.2.5-lp151.6.6 is installed
  • OR php7-xmlreader-7.2.5-lp151.6.6 is installed
  • OR php7-xmlrpc-7.2.5-lp151.6.6 is installed
  • OR php7-xmlwriter-7.2.5-lp151.6.6 is installed
  • OR php7-xsl-7.2.5-lp151.6.6 is installed
  • OR php7-zip-7.2.5-lp151.6.6 is installed
  • OR php7-zlib-7.2.5-lp151.6.6 is installed
  • Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • curl-7.66.0-lp152.3.3 is installed
  • OR curl-mini-7.66.0-lp152.3.3 is installed
  • OR libcurl-devel-7.66.0-lp152.3.3 is installed
  • OR libcurl-devel-32bit-7.66.0-lp152.3.3 is installed
  • OR libcurl-mini-devel-7.66.0-lp152.3.3 is installed
  • OR libcurl4-7.66.0-lp152.3.3 is installed
  • OR libcurl4-32bit-7.66.0-lp152.3.3 is installed
  • OR libcurl4-mini-7.66.0-lp152.3.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND Package Information
  • MozillaFirefox-52.3.0esr-109.3 is installed
  • OR MozillaFirefox-translations-52.3.0esr-109.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND clamav-0.100.3-33.26 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND ucode-intel-20200602-13.68 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • java-1_8_0-ibm-1.8.0_sr6.10-30.69 is installed
  • OR java-1_8_0-ibm-alsa-1.8.0_sr6.10-30.69 is installed
  • OR java-1_8_0-ibm-devel-1.8.0_sr6.10-30.69 is installed
  • OR java-1_8_0-ibm-plugin-1.8.0_sr6.10-30.69 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • dovecot22-2.2.31-19.11 is installed
  • OR dovecot22-backend-mysql-2.2.31-19.11 is installed
  • OR dovecot22-backend-pgsql-2.2.31-19.11 is installed
  • OR dovecot22-backend-sqlite-2.2.31-19.11 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • apache-commons-beanutils-1.9.2-1 is installed
  • OR apache-commons-beanutils-javadoc-1.9.2-1 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND Package Information
  • tomcat-8.0.53-29.27 is installed
  • OR tomcat-admin-webapps-8.0.53-29.27 is installed
  • OR tomcat-docs-webapp-8.0.53-29.27 is installed
  • OR tomcat-el-3_0-api-8.0.53-29.27 is installed
  • OR tomcat-javadoc-8.0.53-29.27 is installed
  • OR tomcat-jsp-2_3-api-8.0.53-29.27 is installed
  • OR tomcat-lib-8.0.53-29.27 is installed
  • OR tomcat-servlet-3_1-api-8.0.53-29.27 is installed
  • OR tomcat-webapps-8.0.53-29.27 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 9 is installed
  • AND Package Information
  • xorg-x11-server-1.19.6-4.8 is installed
  • OR xorg-x11-server-extra-1.19.6-4.8 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND python-cryptography-2.0.3-3.3 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 9 is installed
  • AND python-urllib3-1.23-3.6 is installed
  • BACK