Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 442
Alerts This Week
Warning Icon 1 442

SUSE Tomcat Moderate Security Update Advisory SUSE-2026-3167-1

suse
Calendar Grey July 22, 2026
Scroller Suse
Update resolves multiple issues in Tomcat for SUSE, addressing security and control flaws effectively.
A security update for Tomcat addresses six vulnerabilities in SUSE Linux Enterprise Server 12 SP5, with fixes included in Tomcat version 9.0.119, enhancing overall security.

Summary

## This update for tomcat fixes the following issues Update to Tomcat 9.0.119. Security issues fixed: * CVE-2026-50229: improper neutralization of script-related HTML tags in the number guess example (bsc#1269791). * CVE-2026-53404: always-incorrect control flow implementation in the rewrite valve caused non-OR conditions to be skipped if the first condition in an OR chain matched (bsc#1269910). * CVE-2026-53434: error condition not handled when configuring CRLs for a FFM based connector (bsc#1269824). * CVE-2026-55276: always-incorrect control flow implementation caused special roles and empty authorization constraints to not be included when the effective web.xml was logged (bsc#1269909). * CVE-2026-55955: improper authentication allows a replay attack against the

References

* bsc#1269791

* bsc#1269824

* bsc#1269907

* bsc#1269908

* bsc#1269909

* bsc#1269910

Cross-

* CVE-2026-50229

* CVE-2026-53404

* CVE-2026-53434

* CVE-2026-55276

* CVE-2026-55955

* CVE-2026-55956

CVSS scores:

* CVE-2026-50229 ( SUSE ): 5.3

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

* CVE-2026-50229 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

* CVE-2026-50229 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

* CVE-2026-53404 ( SUSE ): 6.9

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

* CVE-2026-53404 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

* CVE-2026-53404 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

* CVE-2026-53434 ( SUSE ): 6.9

Severity
moderate
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:3167-1
Release Date: 2026-07-21T18:33:27Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.