Explore top 10 tips to secure your open-source projects now. Read More
×tomcat7 could be made to execute arbitrary code.. ========================================================================== Ubuntu Security Notice USN-7282-1 February 21, 2025 tomcat7 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: tomcat7 could be made to execute arbitrary code. Software Description: - tomcat7: Servlet and JSP engine Details: It was discovered that Tomcat incorrectly handled being configured with HTTP PUTs enabled. A remote attacker could use this issue to upload a JSP file to the server and execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS libtomcat7-java 7.0.68-1ubuntu0.4+esm3 Available with Ubuntu Pro tomcat7 7.0.68-1ubuntu0.4+esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7282-1 CVE-2017-12616, CVE-2017-12617 . The Ubuntu Security Announcement USN-7283-1 concerns vulnerabilities in tomcat8, which may permit unauthorized remote code execution.. tomcat7 security, Ubuntu advisory, remote code execution, software vulnerabilities. . Severity: Important. LinuxSecurity.com Team
The package tomcat7 before version 7.0.104-1 is vulnerable to arbitrary code execution. . Arch Linux Security Advisory ASA-202006-6 ======================================== Severity: High Date : 2020-06-06 CVE-ID : CVE-2020-9484 Package : tomcat7 Type : arbitrary code execution Remote : Yes Link : https://security.archlinux.org/AVG-1169 Summary ====== The package tomcat7 before version 7.0.104-1 is vulnerable to arbitrary code execution. Resolution ========= Upgrade to 7.0.104-1. # pacman -Syu "tomcat7> =7.0.104-1" The problem has been fixed upstream in version 7.0.104. Workaround ========= None. Description ========== When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if: a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is configured with sessionAttributeValueClassNameFilter="null" (the default unless a SecurityManager is used) or a sufficiently lax filter to allow the attacker provided object to be deserialized; and d) the attacker knows the relative file path from the storage location used by FileStore to the file the attacker has control over; then, using a specifically crafted request, the attacker will be able to trigger remote code execution via deserialization of the file under their control. Note that all of conditions a) to d) must be true for the attack to succeed. Impact ===== A remote attacker can execute code on the affected host if they control the file content and know the path. References ========= https://lists.apache.org/thread/r77eae567ed829da9012cadb29af17f2df8fa23bf66faf88229857bb1@%3Cannounce.tomcat.apache.org%3E https://security.archlinux.org/CVE-2020-9484 . The Debian Security Bulletin DSA-2021-003 reveals a critical vulnerability in nginx that permits unauthorized access to server files.. Arch Linux, tomcat7 vulnerability, remote code execution, securitybulletin. . LinuxSecurity.com Team
The host name verification in Tomcat when using TLS with the WebSocket client was missing. It is now enabled by default. For Debian 8 "Jessie", this problem has been fixed in version . Package : tomcat7 Version : 7.0.56-3+really7.0.90-1 CVE ID : CVE-2018-8034 The host name verification in Tomcat when using TLS with the WebSocket client was missing. It is now enabled by default. For Debian 8 "Jessie", this problem has been fixed in version 7.0.56-3+really7.0.90-1. We recommend that you upgrade your tomcat7 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS has released a security update for Tomcat7 focusing on TLS host name verification. It is advisable to perform an upgrade to enhance security.. Tomcat7 Update, Debian LTS Security, Host Name Verification, TLS WebSocket, Security Fix. . Severity: Critical. LinuxSecurity.com Team
The security update of Tomcat 7 announced as DLA-1400-1 introduced a regression for applications that make use of the Equinox OSGi framework. The MANIFEST file of tomcat-jdbc.jar in libtomcat7-java contains an invalid version number which was automatically derived . Package : tomcat7 Version : 7.0.56-3+really7.0.88-2 Debian Bug : 902670 The security update of Tomcat 7 announced as DLA-1400-1 introduced a regression for applications that make use of the Equinox OSGi framework. The MANIFEST file of tomcat-jdbc.jar in libtomcat7-java contains an invalid version number which was automatically derived from the Debian package version. This caused an OSGi exception. For Debian 8 "Jessie", this issue has been fixed in version 7.0.56-3+really7.0.88-2. We recommend that you upgrade your tomcat7 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Tomcat 7 security update DLA-1400-2 resolved OSGi regression issue for Debian 8 Jessie, addressing the invalid version error.. Tomcat Update, Debian Tomcat Security, OSGi Framework Issues, Debian Package Updates. . LinuxSecurity.com Team
A remote code execution vulnerability has been discovered in tomcat7. When HTTP PUT was enabled (e.g., via setting the readonly initialization . Package : tomcat7 Version : 7.0.28-4+deb7u16 CVE ID : CVE-2017-12617 A remote code execution vulnerability has been discovered in tomcat7. When HTTP PUT was enabled (e.g., via setting the readonly initialization parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server. For Debian 7 "Wheezy", these problems have been fixed in version 7.0.28-4+deb7u16. We recommend that you upgrade your tomcat7 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A critical security flaw allowing remote code execution in tomcat7 for Debian 7 has been detected and remedied in the new security patch.. remote Code Execution, tomcat7 Update, debian Security. . Severity: Critical. LinuxSecurity.com Team
The package tomcat7 before version 7.0.81-1 is vulnerable to information disclosure. . Arch Linux Security Advisory ASA-201709-17 ========================================= Severity: Medium Date : 2017-09-19 CVE-ID : CVE-2017-12616 Package : tomcat7 Type : information disclosure Remote : Yes Link : https://security.archlinux.org/AVG-408 Summary ====== The package tomcat7 before version 7.0.81-1 is vulnerable to information disclosure. Resolution ========= Upgrade to 7.0.81-1. # pacman -Syu "tomcat7> =7.0.81-1" The problem has been fixed upstream in version 7.0.81. Workaround ========= None. Description ========== It has been discovered that tomcat version 7.0.80 and before are vulnerable to information disclosure. When using a VirtualDirContext it was possible to bypass security constraints and/or view the source code of JSPs for resources served by the VirtualDirContext using a specially crafted request. Impact ===== A remote attacker is able to view the source code of JSPs for resources served by the VirtualDirContext using a specially crafted request. References ========= https://tomcat.apache.org/security-7.html https://lists.apache.org/thread/%
Aniket Nandkishor Kulkarni discovered that in tomcat7, a servlet and JSP engine, static error pages used the original request's HTTP method to serve content, instead of systematically using the GET method. This could under certain conditions result in undesirable results, . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3892-1
The package tomcat7 before version 7.0.78-1 is vulnerable to access restriction bypass. . Arch Linux Security Advisory ASA-201706-6 ======================================== Severity: High Date : 2017-06-06 CVE-ID : CVE-2017-5664 Package : tomcat7 Type : access restriction bypass Remote : Yes Link : https://security.archlinux.org/AVG-290 Summary ====== The package tomcat7 before version 7.0.78-1 is vulnerable to access restriction bypass. Resolution ========= Upgrade to 7.0.78-1. # pacman -Syu "tomcat7> =7.0.78-1" The problem has been fixed upstream in version 7.0.78. Workaround ========= None. Description ========== A security issue has been found in Apache Tomcat < 7.0.18 and < 8.0.44. The error page mechanism of the Java Servlet Specification requires that, when an error occurs and an error page is configured for the error that occurred, the original request and response are forwarded to the error page. This means that the request is presented to the error page with the original HTTP method. If the error page is a static file, expected behaviour is to serve the content of the file as if processing a GET request, regardless of the actual HTTP method. Tomcat's Default Servlet did not do this. Depending on the original request this could lead to unexpected and undesirable results for static error pages including, if the DefaultServlet is configured to permit writes, the replacement or removal of the custom error page. Impact ===== A remote attacker can alter, replace or remove the custom error page of an affected server by sending an HTTP request with a specific method. References ========= https://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.78 https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.0.44 https://security.archlinux.org/CVE-2017-5664 . Enhance tomcat7 on Arch Linux to resolve critical vulnerabilities regarding access control bypass; consult advisory ASA-201706-6 for comprehensiveinformation.. Arch Linux,tomcat7,access restriction,security advisory. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.