Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

SUSE: 2016:0822-2 Critical: Apache HTTP Server Security Vulnerabilities

suse
Calendar Grey March 18, 2016
Dist Suse Esm H88
SUSE Security Patch for tomcat: addresses 7 vulnerabilities, including issues related to session fixation and management weaknesses.
An update that fixes 7 vulnerabilities is now available

Summary

This update for tomcat fixes the following security issues. Tomcat has been updated from 7.0.55 to 7.0.68. * CVE-2015-5174: Directory traversal vulnerability in RequestUtil.java in Apache Tomcat allowed remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via a /.. (slash dot dot) in a pathname used by a web application in a getResource, getResourceAsStream, or getResourcePaths call, as demonstrated by the $CATALINA_BASE/webapps directory. (bsc#967967) * CVE-2015-5346: Session fixation vulnerability in Apache Tomcat when different session settings are used for deployments of multiple versions of the same web application, might have allowed remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field

References

#967812 #967814 #967815 #967964 #967965 #967966

#967967

Cross- CVE-2015-5174 CVE-2015-5345 CVE-2015-5346

CVE-2015-5351 CVE-2016-0706 CVE-2016-0714

CVE-2016-0763

Affected Products:

SUSE Linux Enterprise Server 12

https://www.suse.com/security/cve/CVE-2015-5174.html

https://www.suse.com/security/cve/CVE-2015-5345.html

https://www.suse.com/security/cve/CVE-2015-5346.html

https://www.suse.com/security/cve/CVE-2015-5351.html

https://www.suse.com/security/cve/CVE-2016-0706.html

https://www.suse.com/security/cve/CVE-2016-0714.html

https://www.suse.com/security/cve/CVE-2016-0763.html

https://bugzilla.suse.com/967812

https://bugzilla.suse.com/967814

https://bugzilla.suse.com/967815

https://bugzilla.suse.com/967964

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:0822-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here