Oval Definition:oval:org.opensuse.security:def:70373
Revision Date:2021-04-01Version:1
Title:Security update for tomcat (Important)
Description:

This update for tomcat fixes the following issues:

- CVE-2021-24122: Fixed an information disclosure if resources are served from the NTFS file system (bsc#1180947). - CVE-2021-25122: Apache Tomcat h2c request mix-up (bsc#1182912) - CVE-2021-25329: Complete fix for CVE-2020-9484 (bsc#1182909)
Family:unixClass:patch
Status:Reference(s):1141844
1174052
1175070
1175071
1175074
1180947
1182909
1182912
CVE-2019-13616
CVE-2020-11984
CVE-2020-11993
CVE-2020-9490
CVE-2021-24122
CVE-2021-25122
CVE-2021-25329
SUSE-SU-2020:2311-1
SUSE-SU-2020:3261-1
SUSE-SU-2021:1009-1
Platform(s):SUSE Linux Enterprise Module for Basesystem 15 SP2
SUSE Linux Enterprise Module for Desktop Applications 15 SP2
SUSE Linux Enterprise Server for SAP Applications 15 SP1
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP2 is installed
  • AND Package Information
  • apache2-2.4.43-3.5 is installed
  • OR apache2-prefork-2.4.43-3.5 is installed
  • OR apache2-utils-2.4.43-3.5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Desktop Applications 15 SP2 is installed
  • AND Package Information
  • SDL-1.2.15-3.12 is installed
  • OR libSDL-1_2-0-1.2.15-3.12 is installed
  • OR libSDL-devel-1.2.15-3.12 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server for SAP Applications 15 SP1 is installed
  • AND Package Information
  • tomcat-9.0.36-4.58.1 is installed
  • OR tomcat-admin-webapps-9.0.36-4.58.1 is installed
  • OR tomcat-el-3_0-api-9.0.36-4.58.1 is installed
  • OR tomcat-jsp-2_3-api-9.0.36-4.58.1 is installed
  • OR tomcat-lib-9.0.36-4.58.1 is installed
  • OR tomcat-servlet-4_0-api-9.0.36-4.58.1 is installed
  • OR tomcat-webapps-9.0.36-4.58.1 is installed
  • BACK