Oval Definition:oval:org.opensuse.security:def:60959
Revision Date:2020-12-01Version:1
Title:Security update for tomcat (Important)
Description:

This update for tomcat fixes the following issues:

CVE-2020-9484 (bsc#1171928) Apache Tomcat Remote Code Execution via session persistence

If an attacker was able to control the contents and name of a file on a server configured to use the PersistenceManager, then the attacker could have triggered a remote code execution via deserialization of the file under their control.

CVE-2019-12418 (bsc#1159723) Local privilege escalation by manipulating the RMI registry and performing a man-in-the-middle attack

When Tomcat is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files was able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker could then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.

CVE-2019-0221 (bsc#1136085) The SSI printenv command echoed user provided data without escaping, which made it vulnerable to XSS.

CVE-2019-17563 (bsc#1159729) When using FORM authentication there was a narrow window where an attacker could perform a session fixation attack.

CVE-2019-17569 (bsc#1164825) Invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header.

Family:unixClass:patch
Status:Reference(s):1010201
1012382
1012523
1015336
1015337
1015340
1015342
1015343
1019675
1020412
1020645
1022595
1022607
1024346
1024373
1024376
1024412
1026236
1027519
1031717
1032150
1036304
1036489
1036800
1037404
1037838
1038299
1039542
1040073
1041873
1042268
1042957
1042977
1042978
1043017
1045404
1045735
1046054
1046107
1047901
1047989
1048317
1048327
1048356
1049485
1049488
1049489
1049490
1049491
1049825
1050060
1050231
1051406
1051635
1051987
1052384
1053309
1053919
1055272
1056003
1056334
1056365
1056386
1056427
1056587
1056596
1056652
1056979
1057079
1057199
1057820
1058413
1059639
1060333
1061756
1062496
1062835
1062941
1063026
1063349
1063516
1064206
1064320
1064591
1064597
1064606
1064701
1064926
1065101
1065180
1065600
1065639
1065692
1065717
1065866
1065959
1066045
1066175
1066192
1066213
1066223
1066285
1066382
1066470
1066471
1066472
1066573
1066606
1066629
1066660
1066696
1066767
1066812
1066974
1067105
1067132
1067225
1067494
1067734
1067735
1067888
1067906
1068671
1068978
1068980
1068982
1069152
1069250
1069270
1069277
1069468
1069484
1069583
1069721
1069793
1069879
1069916
1069942
1069996
1070001
1070006
1070145
1070169
1070404
1070535
1070767
1070771
1070805
1070825
1070851
1070964
1071693
1071694
1071695
1071833
1072589
1076192
1081557
1084604
1088705
1091624
1092413
1096803
1099847
1100028
1101349
1102429
1104205
1105528
1109209
1113231
1114957
1114988
1115040
1115045
1115047
1116380
1116717
1117275
1117756
1119161
1119493
1121600
1123156
1123157
1126140
1126141
1126192
1126195
1126196
1126197
1126198
1126201
1126325
1127400
1127820
1127821
1127822
1129623
1131830
1134550
1136085
1138034
1154036
1154037
1159478
1159479
1159482
1159486
1159723
1159729
1159819
1163102
1163103
1163104
1164825
1167976
1168669
1169746
1170908
1171928
1171978
1173022
1173986
1174420
1174922
1174923
1176756
744692
789311
964944
966170
966172
969470
979928
989261
996376
CVE-2017-1000410
CVE-2017-11600
CVE-2017-12193
CVE-2017-13672
CVE-2017-13673
CVE-2017-15115
CVE-2017-16528
CVE-2017-16536
CVE-2017-16537
CVE-2017-16645
CVE-2017-16646
CVE-2017-16994
CVE-2017-17448
CVE-2017-17449
CVE-2017-17450
CVE-2017-18190
CVE-2017-7482
CVE-2017-8824
CVE-2017-9269
CVE-2018-10754
CVE-2018-12178
CVE-2018-12180
CVE-2018-14526
CVE-2018-16872
CVE-2018-18954
CVE-2018-19364
CVE-2018-19489
CVE-2018-19665
CVE-2018-19961
CVE-2018-19962
CVE-2018-19965
CVE-2018-19966
CVE-2018-19967
CVE-2018-3630
CVE-2018-7685
CVE-2018-7858
CVE-2019-0221
CVE-2019-10164
CVE-2019-12418
CVE-2019-15604
CVE-2019-15605
CVE-2019-15606
CVE-2019-17006
CVE-2019-17563
CVE-2019-17569
CVE-2019-17594
CVE-2019-17595
CVE-2019-18388
CVE-2019-18389
CVE-2019-18390
CVE-2019-18391
CVE-2019-6778
CVE-2019-6778
CVE-2019-9824
CVE-2020-12399
CVE-2020-12402
CVE-2020-12673
CVE-2020-12674
CVE-2020-15673
CVE-2020-15676
CVE-2020-15677
CVE-2020-15678
CVE-2020-9484
SUSE-SU-2017:2109-1
SUSE-SU-2017:3398-1
SUSE-SU-2018:0604-1
SUSE-SU-2018:2814-1
SUSE-SU-2019:1783-2
SUSE-SU-2020:0488-1
SUSE-SU-2020:1498-1
SUSE-SU-2020:1839-1
SUSE-SU-2020:2274-1
SUSE-SU-2020:2759-1
Platform(s):openSUSE Leap 15.1
openSUSE Leap 15.2
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server 12 SP4-ESPOS
SUSE OpenStack Cloud Crowbar 8
SUSE OpenStack Cloud Crowbar 9
Product(s):
Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • evince-3.26.0+20180128.1bd86963-lp151.4.6 is installed
  • OR evince-devel-3.26.0+20180128.1bd86963-lp151.4.6 is installed
  • OR evince-lang-3.26.0+20180128.1bd86963-lp151.4.6 is installed
  • OR evince-plugin-comicsdocument-3.26.0+20180128.1bd86963-lp151.4.6 is installed
  • OR evince-plugin-djvudocument-3.26.0+20180128.1bd86963-lp151.4.6 is installed
  • OR evince-plugin-dvidocument-3.26.0+20180128.1bd86963-lp151.4.6 is installed
  • OR evince-plugin-pdfdocument-3.26.0+20180128.1bd86963-lp151.4.6 is installed
  • OR evince-plugin-psdocument-3.26.0+20180128.1bd86963-lp151.4.6 is installed
  • OR evince-plugin-tiffdocument-3.26.0+20180128.1bd86963-lp151.4.6 is installed
  • OR evince-plugin-xpsdocument-3.26.0+20180128.1bd86963-lp151.4.6 is installed
  • OR libevdocument3-4-3.26.0+20180128.1bd86963-lp151.4.6 is installed
  • OR libevview3-3-3.26.0+20180128.1bd86963-lp151.4.6 is installed
  • OR nautilus-evince-3.26.0+20180128.1bd86963-lp151.4.6 is installed
  • OR typelib-1_0-EvinceDocument-3_0-3.26.0+20180128.1bd86963-lp151.4.6 is installed
  • OR typelib-1_0-EvinceView-3_0-3.26.0+20180128.1bd86963-lp151.4.6 is installed
  • Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • openconnect-7.08-lp152.9.4 is installed
  • OR openconnect-devel-7.08-lp152.9.4 is installed
  • OR openconnect-doc-7.08-lp152.9.4 is installed
  • OR openconnect-lang-7.08-lp152.9.4 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND Package Information
  • libtcmu1-1.2.0-2.3 is installed
  • OR tcmu-runner-1.2.0-2.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND Package Information
  • libecpg6-10.9-1.12 is installed
  • OR libpq5-10.9-1.12 is installed
  • OR libpq5-32bit-10.9-1.12 is installed
  • OR postgresql10-10.9-1.12 is installed
  • OR postgresql10-contrib-10.9-1.12 is installed
  • OR postgresql10-docs-10.9-1.12 is installed
  • OR postgresql10-libs-10.9-1.12 is installed
  • OR postgresql10-plperl-10.9-1.12 is installed
  • OR postgresql10-plpython-10.9-1.12 is installed
  • OR postgresql10-pltcl-10.9-1.12 is installed
  • OR postgresql10-server-10.9-1.12 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND Package Information
  • libvirglrenderer0-0.5.0-12.3 is installed
  • OR virglrenderer-0.5.0-12.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND wpa_supplicant-2.6-15.10 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • apache-commons-beanutils-1.9.2-1 is installed
  • OR apache-commons-beanutils-javadoc-1.9.2-1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-ESPOS is installed
  • AND Package Information
  • libpython3_4m1_0-3.4.10-25.52 is installed
  • OR python3-3.4.10-25.52 is installed
  • OR python3-base-3.4.10-25.52 is installed
  • OR python3-curses-3.4.10-25.52 is installed
  • OR python3-devel-3.4.10-25.52 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND Package Information
  • tomcat-8.0.53-29.27 is installed
  • OR tomcat-admin-webapps-8.0.53-29.27 is installed
  • OR tomcat-docs-webapp-8.0.53-29.27 is installed
  • OR tomcat-el-3_0-api-8.0.53-29.27 is installed
  • OR tomcat-javadoc-8.0.53-29.27 is installed
  • OR tomcat-jsp-2_3-api-8.0.53-29.27 is installed
  • OR tomcat-lib-8.0.53-29.27 is installed
  • OR tomcat-servlet-3_1-api-8.0.53-29.27 is installed
  • OR tomcat-webapps-8.0.53-29.27 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 9 is installed
  • AND Package Information
  • openstack-manila-7.3.1~dev15-4.18 is installed
  • OR openstack-manila-api-7.3.1~dev15-4.18 is installed
  • OR openstack-manila-data-7.3.1~dev15-4.18 is installed
  • OR openstack-manila-scheduler-7.3.1~dev15-4.18 is installed
  • OR openstack-manila-share-7.3.1~dev15-4.18 is installed
  • OR python-manila-7.3.1~dev15-4.18 is installed
  • BACK