This update for tomcat fixes the following issues: Tomcat 8 was updated from 8.0.23 to 8.0.32, to fix bugs and security issues. Fixed security issues: * CVE-2015-5174: Directory traversal vulnerability in RequestUtil.java in Apache Tomcat allowed remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via a /.. (slash dot dot) in a pathname used by a web application in a getResource, getResourceAsStream, or getResourcePaths call, as demonstrated by the $CATALINA_BASE/webapps directory. (bsc#967967) * CVE-2015-5346: Session fixation vulnerability in Apache Tomcat when different session settings are used for deployments of multiple versions of the same web application, might have allowed remote attackers to
#967812 #967814 #967815 #967964 #967965 #967966
#967967
Cross- CVE-2015-5174 CVE-2015-5345 CVE-2015-5346
CVE-2015-5351 CVE-2016-0706 CVE-2016-0714
CVE-2016-0763
Affected Products:
SUSE Linux Enterprise Server 12-SP1
https://www.suse.com/security/cve/CVE-2015-5174.html
https://www.suse.com/security/cve/CVE-2015-5345.html
https://www.suse.com/security/cve/CVE-2015-5346.html
https://www.suse.com/security/cve/CVE-2015-5351.html
https://www.suse.com/security/cve/CVE-2016-0706.html
https://www.suse.com/security/cve/CVE-2016-0714.html
https://www.suse.com/security/cve/CVE-2016-0763.html
https://bugzilla.suse.com/967812
https://bugzilla.suse.com/967814
https://bugzilla.suse.com/967815
https://bugzilla.suse.com/967964
Get the latest Linux and open source security news straight to your inbox.