Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 569
Alerts This Week
Warning Icon 1 569

SUSE LE 15 SP5: 2025:1024-1 important: tomcat10 critical fixes

suse
Calendar Grey March 26, 2025
Scroller Suse
This notice outlines essential changes for tomcat10 focusing on significant vulnerabilities, encompassing remote code execution and safeguarding sensitive information.
* bsc#1239302 * bsc#1239676 Cross-References: * CVE-2024-56337

Summary

## This update for tomcat10 fixes the following issues: * CVE-2025-24813: Fixed potential RCE and/or information disclosure/corruption with partial PUT (bsc#1239302) Other fixes: * Update to Tomcat 10.1.39 * Fixes: * launch with java 17 (bsc#1239676) * Catalina * Fix: 69602: Fix regression in releases from 12-2024 that were too strict and rejected weak etags in the If-Range header with a 400 response. Instead will consider it as a failed match since strong etags are required for If-Range. (remm)

References

* bsc#1239302

* bsc#1239676

Cross-

* CVE-2024-56337

* CVE-2025-24813

CVSS scores:

* CVE-2024-56337 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

* CVE-2024-56337 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

* CVE-2025-24813 ( SUSE ): 9.2

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

* CVE-2025-24813 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

* CVE-2025-24813 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

* CVE-2025-24813 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products:

* openSUSE Leap 15.6

* SUSE Linux Enterprise High Performance Computing 15 SP5

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2025:1024-1
Release Date: 2025-03-26T11:29:29Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.