Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update for tomcat fixes the following issues:
Tomcat 8 was updated from 8.0.23 to 8.0.32, to fix bugs and security
issues.
Fixed security issues:
* CVE-2015-5174: Directory traversal vulnerability in RequestUtil.java in
Apache Tomcat allowed remote authenticated users to bypass intended
SecurityManager restrictions and list a parent directory via a /..
(slash dot dot) in a pathname used by a web application in a
getResource, getResourceAsStream, or getResourcePaths call, as
demonstrated by the $CATALINA_BASE/webapps directory. (bsc#967967)
* CVE-2015-5346: Session fixation vulnerability in Apache Tomcat when
different session settings are used for deployments of multiple versions
of the same web application, might have allowed remote attackers to
hijack web sessions by leveraging use of a requestedSessionSSL field
for an unintended request, related to CoyoteAdapter.java and
Request.java. (bsc#967814)
...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE Leap 42.1:
zypper in -t patch openSUSE-2016-384=1
To bring your system up-to-date, use "zypper patch".
- openSUSE Leap 42.1 (noarch):
tomcat-8.0.32-5.1
tomcat-admin-webapps-8.0.32-5.1
tomcat-docs-webapp-8.0.32-5.1
tomcat-el-3_0-api-8.0.32-5.1
tomcat-embed-8.0.32-5.1
tomcat-javadoc-8.0.32-5.1
tomcat-jsp-2_3-api-8.0.32-5.1
tomcat-jsvc-8.0.32-5.1
tomcat-lib-8.0.32-5.1
tomcat-servlet-3_1-api-8.0.32-5.1
tomcat-webapps-8.0.32-5.1
https://www.suse.com/security/cve/CVE-2015-5174.html
https://www.suse.com/security/cve/CVE-2015-5345.html
https://www.suse.com/security/cve/CVE-2015-5346.html
https://www.suse.com/security/cve/CVE-2015-5351.html
https://www.suse.com/security/cve/CVE-2016-0706.html
https://www.suse.com/security/cve/CVE-2016-0714.html
https://www.suse.com/security/cve/CVE-2016-0763.html
https://bugzilla.suse.com/show_bug.cgi?id=967812
https://bugzilla.suse.com/show_bug.cgi?id=967814
https://bugzilla.suse.com/show_bug.cgi?id=967815
https://bugzilla.suse.com/show_bug.cgi?id=967964
https://bugzilla.suse.com/show_bug.cgi?id=967965
https://bugzilla.suse.com/show_bug.cgi?id=967966
https://bugzilla.suse.com/967967
Get the latest Linux and open source security news straight to your inbox.