Oval Definition:oval:org.opensuse.security:def:64118
Revision Date:2020-12-01Version:1
Title:Security update for tomcat (Important)
Description:

This update for tomcat fixes the following issues:

Tomcat was updated to 9.0.36 See changelog at

- CVE-2020-11996: Fixed an issue which by sending a specially crafted sequence of HTTP/2 requests could have triggered high CPU usage for several seconds making potentially the server unresponsive (bsc#1173389).
Family:unixClass:patch
Status:Reference(s):1027519
1046299
1046303
1046305
1050244
1050536
1050545
1051510
1055186
1061840
1064802
1065600
1066129
1073513
1082635
1083647
1086323
1087092
1089644
1093205
1097583
1097584
1097585
1097586
1097587
1097588
1098291
1101674
1109158
1111666
1112178
1113994
1114279
1117665
1123034
1123080
1123334
1133140
1134303
1135642
1135854
1135873
1137040
1137799
1137861
1140729
1140845
1140883
1141600
1141853
1142635
1142667
1143706
1144338
1144375
1144449
1145099
1146612
1148410
1149853
1150452
1150457
1150465
1150875
1151508
1151807
1152033
1152624
1152685
1152788
1152790
1152791
1153112
1153158
1153236
1153263
1153476
1153509
1153607
1153646
1153713
1153717
1153718
1153719
1153811
1153969
1154108
1154189
1154242
1154268
1154354
1154372
1154521
1154578
1154607
1154608
1154610
1154611
1154651
1154737
1154747
1154848
1155178
1155179
1155184
1155186
1160790
1161088
1161089
1161670
1173389
1174711
1175505
1175534
1176339
1176343
1176344
1176345
1176346
1176347
1176348
1176349
1176350
CVE-2011-0461
CVE-2018-20743
CVE-2018-20852
CVE-2019-16232
CVE-2019-16233
CVE-2019-16234
CVE-2019-16785
CVE-2019-16786
CVE-2019-16789
CVE-2019-16792
CVE-2019-16995
CVE-2019-17056
CVE-2019-17133
CVE-2019-17666
CVE-2020-11996
CVE-2020-14364
CVE-2020-16118
CVE-2020-25595
CVE-2020-25596
CVE-2020-25597
CVE-2020-25599
CVE-2020-25600
CVE-2020-25601
CVE-2020-25602
CVE-2020-25603
CVE-2020-25604
CVE-2020-6556
openSUSE-SU-2019:1794-1
openSUSE-SU-2019:1989-1
openSUSE-SU-2019:2444-1
openSUSE-SU-2020:1207-1
openSUSE-SU-2020:1263-1
SUSE-SU-2020:1963-1
SUSE-SU-2020:2786-1
Platform(s):openSUSE Leap 15.1
openSUSE Leap 15.2
SUSE Linux Enterprise Module for Basesystem 15 SP1
SUSE Linux Enterprise Server 12 SP4-LTSS
Product(s):
Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • mumble-1.2.19-9 is installed
  • OR mumble-32bit-1.2.19-lp151.4.6 is installed
  • OR mumble-server-1.2.19-9 is installed
  • Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • chromedriver-84.0.4147.135-lp152.2.17 is installed
  • OR chromium-84.0.4147.135-lp152.2.17 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP1 is installed
  • AND Package Information
  • aaa_base-84.87+git20180409.04c9dae-3.6 is installed
  • OR aaa_base-extras-84.87+git20180409.04c9dae-3.6 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-LTSS is installed
  • AND Package Information
  • tomcat-9.0.36-3.42 is installed
  • OR tomcat-admin-webapps-9.0.36-3.42 is installed
  • OR tomcat-docs-webapp-9.0.36-3.42 is installed
  • OR tomcat-el-3_0-api-9.0.36-3.42 is installed
  • OR tomcat-javadoc-9.0.36-3.42 is installed
  • OR tomcat-jsp-2_3-api-9.0.36-3.42 is installed
  • OR tomcat-lib-9.0.36-3.42 is installed
  • OR tomcat-servlet-4_0-api-9.0.36-3.42 is installed
  • OR tomcat-webapps-9.0.36-3.42 is installed
  • BACK