Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Debian LTS: DLA-2155-1 Critical: Tomcat8 Man-In-The-Middle Attack

debian lts
Calendar Grey March 24, 2020
Dist Debian Esm H88
Tomcat9 security patch addresses a vulnerability in the AJP connector that could allow remote exploitation, enabling unauthorized access to the server.
Tomcat8 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to...

Summary

For Debian 8 "Jessie", this problem has been fixed in version
8.0.14-1+deb8u16.

We recommend that you upgrade your tomcat8 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

Package: tomcat8
Version: 8.0.14-1+deb8u16
CVE ID: CVE-2019-12418

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here