-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Important: tomcat6 security update
Advisory ID:       RHSA-2020:2529-01
Product:           Red Hat Enterprise Linux
Advisory URL:      https://access.redhat.com/errata/RHSA-2020:2529
Issue date:        2020-06-11
CVE Names:         CVE-2020-9484 
====================================================================
1. Summary:

An update for tomcat6 is now available for Red Hat Enterprise Linux 6.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat Enterprise Linux Desktop Optional (v. 6) - noarch
Red Hat Enterprise Linux HPC Node Optional (v. 6) - noarch
Red Hat Enterprise Linux Server (v. 6) - noarch
Red Hat Enterprise Linux Server Optional (v. 6) - noarch
Red Hat Enterprise Linux Workstation (v. 6) - noarch
Red Hat Enterprise Linux Workstation Optional (v. 6) - noarch

3. Description:

Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.

Security Fix(es):

* tomcat: deserialization flaw in session persistence storage leading to
RCE (CVE-2020-9484)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

4. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

5. Bugs fixed (https://bugzilla.redhat.com/):

1838332 - CVE-2020-9484 tomcat: deserialization flaw in session persistence storage leading to RCE

6. Package List:

Red Hat Enterprise Linux Desktop Optional (v. 6):

Source:
tomcat6-6.0.24-115.el6_10.src.rpm

noarch:
tomcat6-6.0.24-115.el6_10.noarch.rpm
tomcat6-admin-webapps-6.0.24-115.el6_10.noarch.rpm
tomcat6-docs-webapp-6.0.24-115.el6_10.noarch.rpm
tomcat6-el-2.1-api-6.0.24-115.el6_10.noarch.rpm
tomcat6-javadoc-6.0.24-115.el6_10.noarch.rpm
tomcat6-jsp-2.1-api-6.0.24-115.el6_10.noarch.rpm
tomcat6-lib-6.0.24-115.el6_10.noarch.rpm
tomcat6-servlet-2.5-api-6.0.24-115.el6_10.noarch.rpm
tomcat6-webapps-6.0.24-115.el6_10.noarch.rpm

Red Hat Enterprise Linux HPC Node Optional (v. 6):

Source:
tomcat6-6.0.24-115.el6_10.src.rpm

noarch:
tomcat6-6.0.24-115.el6_10.noarch.rpm
tomcat6-admin-webapps-6.0.24-115.el6_10.noarch.rpm
tomcat6-docs-webapp-6.0.24-115.el6_10.noarch.rpm
tomcat6-el-2.1-api-6.0.24-115.el6_10.noarch.rpm
tomcat6-javadoc-6.0.24-115.el6_10.noarch.rpm
tomcat6-jsp-2.1-api-6.0.24-115.el6_10.noarch.rpm
tomcat6-lib-6.0.24-115.el6_10.noarch.rpm
tomcat6-servlet-2.5-api-6.0.24-115.el6_10.noarch.rpm
tomcat6-webapps-6.0.24-115.el6_10.noarch.rpm

Red Hat Enterprise Linux Server (v. 6):

Source:
tomcat6-6.0.24-115.el6_10.src.rpm

noarch:
tomcat6-6.0.24-115.el6_10.noarch.rpm
tomcat6-el-2.1-api-6.0.24-115.el6_10.noarch.rpm
tomcat6-jsp-2.1-api-6.0.24-115.el6_10.noarch.rpm
tomcat6-lib-6.0.24-115.el6_10.noarch.rpm
tomcat6-servlet-2.5-api-6.0.24-115.el6_10.noarch.rpm

Red Hat Enterprise Linux Server Optional (v. 6):

noarch:
tomcat6-admin-webapps-6.0.24-115.el6_10.noarch.rpm
tomcat6-docs-webapp-6.0.24-115.el6_10.noarch.rpm
tomcat6-javadoc-6.0.24-115.el6_10.noarch.rpm
tomcat6-webapps-6.0.24-115.el6_10.noarch.rpm

Red Hat Enterprise Linux Workstation (v. 6):

Source:
tomcat6-6.0.24-115.el6_10.src.rpm

noarch:
tomcat6-6.0.24-115.el6_10.noarch.rpm
tomcat6-el-2.1-api-6.0.24-115.el6_10.noarch.rpm
tomcat6-jsp-2.1-api-6.0.24-115.el6_10.noarch.rpm
tomcat6-lib-6.0.24-115.el6_10.noarch.rpm
tomcat6-servlet-2.5-api-6.0.24-115.el6_10.noarch.rpm

Red Hat Enterprise Linux Workstation Optional (v. 6):

noarch:
tomcat6-admin-webapps-6.0.24-115.el6_10.noarch.rpm
tomcat6-docs-webapp-6.0.24-115.el6_10.noarch.rpm
tomcat6-javadoc-6.0.24-115.el6_10.noarch.rpm
tomcat6-webapps-6.0.24-115.el6_10.noarch.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2020-9484
https://access.redhat.com/security/updates/classification/#important

8. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2020 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBXuIAOtzjgjWX9erEAQircxAAiJgOBZ2LET65r7XgAUP0MKNR8/ftKZkx
VCnUU/yGylYEi5x7PODw8u/wGpmgbaC6rOfsHOETf/SEeUII2CgBUrK4A84/+ySc
hxxUZJYJju5F2GcUsneictfVRJhdgehZuD/1Xa8M+x39TwAOqEH6U6+lKjZjCZCE
oGLm8zXXePN21rsuF342CsI1/Z0ecCbYZgsIbvNksmtFWkqAsoprJNOJX7mz8QSd
wd/mo85aWcL3e3EO9hClLD6wsX4UiiEn6zkuWgtucgqhaX8DnCwRh6aRHvHZBUtO
TC+F2gmxl6jqFqK3Yy9Q7VYY5Cf7eeePzDgIVdPOuNuxNQh1y6QIPe+rt1WqNhaF
+p+WgjB1GTRoUIQKQ3XwvI4zBypD01ZnZLUicUBMhenOBm8DfeYZ4UusMrJi3AVs
rj7ElHVQtBT5S2SkF7RJGPcFV6/UY0XatHHZMZ19ugwiOED+uCpCO3EH/lQbAOLf
Ei5Wb6a9uyNGfp/qFuHPzQzGlYr3EVwiv6EL0ME8tclXzV38LWEllQHAAkjGrYv/
xPDFbY4uvK9w26hQyqElycB4wJcn6c3i5D05TDUg92fE+TQ5O9nFlcDV3E+VafoZ
sP45dVLPlUh307m/OhCgctbqLcnLef/mQJrUzwc3FR6/AI+R5WAekP47OEJd/Min
JP21Ib3I3uM=oD9n
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2020-2529:01 Important: tomcat6 security update

An update for tomcat6 is now available for Red Hat Enterprise Linux 6

Summary

Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies.
Security Fix(es):
* tomcat: deserialization flaw in session persistence storage leading to RCE (CVE-2020-9484)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2020-9484 https://access.redhat.com/security/updates/classification/#important

Package List

Red Hat Enterprise Linux Desktop Optional (v. 6):
Source: tomcat6-6.0.24-115.el6_10.src.rpm
noarch: tomcat6-6.0.24-115.el6_10.noarch.rpm tomcat6-admin-webapps-6.0.24-115.el6_10.noarch.rpm tomcat6-docs-webapp-6.0.24-115.el6_10.noarch.rpm tomcat6-el-2.1-api-6.0.24-115.el6_10.noarch.rpm tomcat6-javadoc-6.0.24-115.el6_10.noarch.rpm tomcat6-jsp-2.1-api-6.0.24-115.el6_10.noarch.rpm tomcat6-lib-6.0.24-115.el6_10.noarch.rpm tomcat6-servlet-2.5-api-6.0.24-115.el6_10.noarch.rpm tomcat6-webapps-6.0.24-115.el6_10.noarch.rpm
Red Hat Enterprise Linux HPC Node Optional (v. 6):
Source: tomcat6-6.0.24-115.el6_10.src.rpm
noarch: tomcat6-6.0.24-115.el6_10.noarch.rpm tomcat6-admin-webapps-6.0.24-115.el6_10.noarch.rpm tomcat6-docs-webapp-6.0.24-115.el6_10.noarch.rpm tomcat6-el-2.1-api-6.0.24-115.el6_10.noarch.rpm tomcat6-javadoc-6.0.24-115.el6_10.noarch.rpm tomcat6-jsp-2.1-api-6.0.24-115.el6_10.noarch.rpm tomcat6-lib-6.0.24-115.el6_10.noarch.rpm tomcat6-servlet-2.5-api-6.0.24-115.el6_10.noarch.rpm tomcat6-webapps-6.0.24-115.el6_10.noarch.rpm
Red Hat Enterprise Linux Server (v. 6):
Source: tomcat6-6.0.24-115.el6_10.src.rpm
noarch: tomcat6-6.0.24-115.el6_10.noarch.rpm tomcat6-el-2.1-api-6.0.24-115.el6_10.noarch.rpm tomcat6-jsp-2.1-api-6.0.24-115.el6_10.noarch.rpm tomcat6-lib-6.0.24-115.el6_10.noarch.rpm tomcat6-servlet-2.5-api-6.0.24-115.el6_10.noarch.rpm
Red Hat Enterprise Linux Server Optional (v. 6):
noarch: tomcat6-admin-webapps-6.0.24-115.el6_10.noarch.rpm tomcat6-docs-webapp-6.0.24-115.el6_10.noarch.rpm tomcat6-javadoc-6.0.24-115.el6_10.noarch.rpm tomcat6-webapps-6.0.24-115.el6_10.noarch.rpm
Red Hat Enterprise Linux Workstation (v. 6):
Source: tomcat6-6.0.24-115.el6_10.src.rpm
noarch: tomcat6-6.0.24-115.el6_10.noarch.rpm tomcat6-el-2.1-api-6.0.24-115.el6_10.noarch.rpm tomcat6-jsp-2.1-api-6.0.24-115.el6_10.noarch.rpm tomcat6-lib-6.0.24-115.el6_10.noarch.rpm tomcat6-servlet-2.5-api-6.0.24-115.el6_10.noarch.rpm
Red Hat Enterprise Linux Workstation Optional (v. 6):
noarch: tomcat6-admin-webapps-6.0.24-115.el6_10.noarch.rpm tomcat6-docs-webapp-6.0.24-115.el6_10.noarch.rpm tomcat6-javadoc-6.0.24-115.el6_10.noarch.rpm tomcat6-webapps-6.0.24-115.el6_10.noarch.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/


Severity
Advisory ID: RHSA-2020:2529-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2020:2529
Issued Date: : 2020-06-11
CVE Names: CVE-2020-9484

Topic

An update for tomcat6 is now available for Red Hat Enterprise Linux 6.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures

Red Hat Enterprise Linux Desktop Optional (v. 6) - noarch

Red Hat Enterprise Linux HPC Node Optional (v. 6) - noarch

Red Hat Enterprise Linux Server (v. 6) - noarch

Red Hat Enterprise Linux Server Optional (v. 6) - noarch

Red Hat Enterprise Linux Workstation (v. 6) - noarch

Red Hat Enterprise Linux Workstation Optional (v. 6) - noarch


Bugs Fixed

1838332 - CVE-2020-9484 tomcat: deserialization flaw in session persistence storage leading to RCE


Related News