[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2017:3039-1 -- SLES tomcat

ID: oval:org.secpod.oval:def:89044662Date: (C)2021-07-07   (M)2023-12-14
Class: PATCHFamily: unix




This update for tomcat fixes the following issues: Security issues fixed: - CVE-2017-5664: A problem in handling error pages was fixed, to avoid potential file overwrites during error page handling. - CVE-2017-7674: A CORS Filter issue could lead to client and server side cache poisoning - CVE-2017-12617: A remote code execution possibility via JSP Upload was fixed Non security bugs fixed: - Fix tomcat-digest classpath error - Fix packaged /etc/alternatives symlinks for api libs that caused rpm -V to report link mismatch

Platform:
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP2
Product:
tomcat
Reference:
SUSE-SU-2017:3039-1
CVE-2017-12617
CVE-2017-5664
CVE-2017-7674
CVE    3
CVE-2017-5664
CVE-2017-7674
CVE-2017-12617
CPE    169
cpe:/a:apache:tomcat:7.0.71
cpe:/a:apache:tomcat:7.0.70
cpe:/a:apache:tomcat:7.0.62
cpe:/a:apache:tomcat:7.0.61
...

© SecPod Technologies