Oval Definition:oval:org.opensuse.security:def:63934
Revision Date:2020-12-01Version:1
Title:Security update for tomcat (Important)
Description:

This update for tomcat fixes the following issues:

- Update to Tomcat 9.0.35. See changelog at http://tomcat.apache.org/tomcat-9.0-doc/changelog.html#Tomcat_9.0.35_(markt)

CVE-2020-9484 (bsc#1171928) Apache Tomcat Remote Code Execution via session persistence

If an attacker was able to control the contents and name of a file on a server configured to use the PersistenceManager, then the attacker could have triggered a remote code execution via deserialization of the file under their control.



Family:unixClass:patch
Status:Reference(s):1024288
1024291
1132665
1136936
1148728
1158108
1158109
1162689
1162691
1166238
1167373
1169659
1170313
1171928
1172906
1172935
1173197
1173389
1175476
1175674
1176579
CVE-2017-2579
CVE-2017-2580
CVE-2019-12519
CVE-2019-12521
CVE-2019-12528
CVE-2019-14562
CVE-2019-14861
CVE-2019-14870
CVE-2019-15757
CVE-2019-18860
CVE-2019-20503
CVE-2020-11945
CVE-2020-11996
CVE-2020-14093
CVE-2020-14154
CVE-2020-1472
CVE-2020-14954
CVE-2020-6805
CVE-2020-6806
CVE-2020-6807
CVE-2020-6811
CVE-2020-6812
CVE-2020-6814
CVE-2020-8517
CVE-2020-9484
openSUSE-SU-2019:1605-1
openSUSE-SU-2019:2096-1
openSUSE-SU-2019:2700-1
openSUSE-SU-2020:0623-1
openSUSE-SU-2020:1526-1
SUSE-SU-2020:0717-1
SUSE-SU-2020:1365-1
SUSE-SU-2020:1794-1
SUSE-SU-2020:1963-1
Platform(s):openSUSE Leap 15.1
openSUSE Leap 15.2
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server 12 SP4-ESPOS
SUSE Linux Enterprise Server 12 SP4-LTSS
Product(s):
Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • libnetpbm-devel-10.80.1-lp151.4.3 is installed
  • OR libnetpbm11-10.80.1-lp151.4.3 is installed
  • OR libnetpbm11-32bit-10.80.1-lp151.4.3 is installed
  • OR netpbm-10.80.1-lp151.4.3 is installed
  • OR netpbm-vulnerable-10.80.1-lp151.4.3 is installed
  • Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • ctdb-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR ctdb-pcp-pmda-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR ctdb-tests-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libdcerpc-binding0-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libdcerpc-binding0-32bit-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libdcerpc-devel-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libdcerpc-samr-devel-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libdcerpc-samr0-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libdcerpc-samr0-32bit-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libdcerpc0-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libdcerpc0-32bit-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libndr-devel-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libndr-krb5pac-devel-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libndr-krb5pac0-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libndr-krb5pac0-32bit-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libndr-nbt-devel-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libndr-nbt0-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libndr-nbt0-32bit-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libndr-standard-devel-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libndr-standard0-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libndr-standard0-32bit-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libndr0-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libndr0-32bit-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libnetapi-devel-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libnetapi-devel-32bit-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libnetapi0-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libnetapi0-32bit-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libsamba-credentials-devel-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libsamba-credentials0-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libsamba-credentials0-32bit-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libsamba-errors-devel-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libsamba-errors0-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libsamba-errors0-32bit-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libsamba-hostconfig-devel-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libsamba-hostconfig0-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libsamba-hostconfig0-32bit-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libsamba-passdb-devel-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libsamba-passdb0-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libsamba-passdb0-32bit-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libsamba-policy-devel-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libsamba-policy-python3-devel-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libsamba-policy0-python3-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libsamba-policy0-python3-32bit-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libsamba-util-devel-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libsamba-util0-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libsamba-util0-32bit-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libsamdb-devel-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libsamdb0-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libsamdb0-32bit-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libsmbclient-devel-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libsmbclient0-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libsmbclient0-32bit-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libsmbconf-devel-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libsmbconf0-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libsmbconf0-32bit-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libsmbldap-devel-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libsmbldap2-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libsmbldap2-32bit-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libtevent-util-devel-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libtevent-util0-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libtevent-util0-32bit-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libwbclient-devel-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libwbclient0-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR libwbclient0-32bit-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR samba-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR samba-ad-dc-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR samba-ad-dc-32bit-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR samba-ceph-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR samba-client-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR samba-client-32bit-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR samba-core-devel-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR samba-doc-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR samba-dsdb-modules-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR samba-libs-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR samba-libs-32bit-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR samba-libs-python3-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR samba-libs-python3-32bit-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR samba-python3-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR samba-test-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR samba-winbind-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • OR samba-winbind-32bit-4.11.13+git.189.e9bd318cd13-lp152.3.13 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • tomcat-9.0.35-3.32 is installed
  • OR tomcat-admin-webapps-9.0.35-3.32 is installed
  • OR tomcat-docs-webapp-9.0.35-3.32 is installed
  • OR tomcat-el-3_0-api-9.0.35-3.32 is installed
  • OR tomcat-javadoc-9.0.35-3.32 is installed
  • OR tomcat-jsp-2_3-api-9.0.35-3.32 is installed
  • OR tomcat-lib-9.0.35-3.32 is installed
  • OR tomcat-servlet-4_0-api-9.0.35-3.32 is installed
  • OR tomcat-webapps-9.0.35-3.32 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-ESPOS is installed
  • AND Package Information
  • ovmf-2017+git1510945757.b2662641d5-3.29 is installed
  • OR ovmf-tools-2017+git1510945757.b2662641d5-3.29 is installed
  • OR qemu-ovmf-x86_64-2017+git1510945757.b2662641d5-3.29 is installed
  • OR qemu-uefi-aarch64-2017+git1510945757.b2662641d5-3.29 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-LTSS is installed
  • AND Package Information
  • tomcat-9.0.36-3.42 is installed
  • OR tomcat-admin-webapps-9.0.36-3.42 is installed
  • OR tomcat-docs-webapp-9.0.36-3.42 is installed
  • OR tomcat-el-3_0-api-9.0.36-3.42 is installed
  • OR tomcat-javadoc-9.0.36-3.42 is installed
  • OR tomcat-jsp-2_3-api-9.0.36-3.42 is installed
  • OR tomcat-lib-9.0.36-3.42 is installed
  • OR tomcat-servlet-4_0-api-9.0.36-3.42 is installed
  • OR tomcat-webapps-9.0.36-3.42 is installed
  • BACK