Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

SUSE: 2025:02280-1 critical: tomcat vulnerabilities and security risks

suse
Calendar Grey July 10, 2025
Dist Suse Esm H88
Recent SUSE update tackles critical tomcat security flaws, offering solutions for various vulnerabilities. Immediate upgrade advised.
* bsc#1242722 * bsc#1243815 * bsc#1244649 * bsc#1244656

Summary

## This update for tomcat fixes the following issues: * CVE-2025-46701: Fixed refactor CGI servlet to access resources via WebResources (bsc#1243815). * CVE-2025-48988: Fixed limits the total number of parts in a multi-part request and limits the size of the headers provided with each part (bsc#1244656). * CVE-2025-49125: Fixed expand checks for webAppMount (bsc#1244649). Other bugfixes: * Made permissions more secure (bsc#1242722) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-2280=1 * Web and Scripting Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP6-2025-2280=1

References

* bsc#1242722

* bsc#1243815

* bsc#1244649

* bsc#1244656

Cross-

* CVE-2025-46701

* CVE-2025-48988

* CVE-2025-49125

CVSS scores:

* CVE-2025-46701 ( SUSE ): 6.3

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

* CVE-2025-46701 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

* CVE-2025-46701 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

* CVE-2025-48988 ( SUSE ): 8.7

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2025-48988 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2025-48988 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2025-49125 ( SUSE ): 9.1

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2025:02280-1
Release Date: 2025-07-10T16:05:23Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here