Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

openSUSE Leap: 2025:15304-1 critical: apache2 security updates

opensuse
Calendar Grey July 5, 2025
Scroller Opensuse
This alert outlines significant security flaws in Tomcat for openSUSE Tumbleweed, prompting users to promptly refresh their systems.
An update that solves 3 vulnerabilities can now be installed.

Description

These are all security issues fixed in the tomcat11-11.0.8-1.1 package on the GA media of openSUSE Tumbleweed.

Patch

Package List

* openSUSE Tumbleweed:

* tomcat11 11.0.8-1.1

* tomcat11-admin-webapps 11.0.8-1.1

* tomcat11-doc 11.0.8-1.1

* tomcat11-docs-webapp 11.0.8-1.1

* tomcat11-el-6_0-api 11.0.8-1.1

* tomcat11-embed 11.0.8-1.1

* tomcat11-jsp-4_0-api 11.0.8-1.1

* tomcat11-jsvc 11.0.8-1.1

* tomcat11-lib 11.0.8-1.1

* tomcat11-servlet-6_1-api 11.0.8-1.1

* tomcat11-webapps 11.0.8-1.1

References

* https://www.suse.com/security/cve/CVE-2025-46701.html

* https://www.suse.com/security/cve/CVE-2025-48988.html

* https://www.suse.com/security/cve/CVE-2025-49125.html

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2025:15303-1
Rating: moderate
Affected Products: * openSUSE Tumbleweed

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.