[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2016:3081-1 -- SLES tomcat

ID: oval:org.secpod.oval:def:89045371Date: (C)2021-08-03   (M)2023-12-14
Class: PATCHFamily: unix




This update for tomcat fixes the following issues: Feature changes: The embedded Apache Commons DBCP component was updated to version 2.0. Security fixes: - CVE-2016-0762: Realm Timing Attack - CVE-2016-5018: Security Manager Bypass - CVE-2016-6794: System Property Disclosure - CVE-2016-6796: Security Manager Bypass - CVE-2016-6797: Unrestricted Access to Global Resources - CVE-2016-8735: Remote code execution vulnerability in JmxRemoteLifecycleListener - CVE-2016-6816: HTTP Request smuggling vulnerability due to permitting invalid character in HTTP requests Bug fixes: - Enabled optional setenv.sh script

Platform:
SUSE Linux Enterprise Server 12 SP2
Product:
tomcat
Reference:
SUSE-SU-2016:3081-1
CVE-2016-0762
CVE-2016-5018
CVE-2016-6794
CVE-2016-6796
CVE-2016-6797
CVE-2016-6816
CVE-2016-8735
CVE    7
CVE-2016-0762
CVE-2016-5018
CVE-2016-6796
CVE-2016-6797
...
CPE    177
cpe:/a:apache:tomcat:6.0.47
cpe:/a:apache:tomcat:6.0.46
cpe:/a:apache:tomcat:6.0.43
cpe:/a:apache:tomcat:6.0.42
...

© SecPod Technologies