[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

255116

 
 

909

 
 

198683

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2020:0632-1 -- SLES tomcat

ID: oval:org.secpod.oval:def:89043860Date: (C)2021-03-05   (M)2024-05-09
Class: PATCHFamily: unix




This update for tomcat to version 9.0.31 fixes the following issues: Security issues fixed: - CVE-2019-10072: Fixed a denial-of-service that could have been caused by clients omitting WINDOW_UPDATE messages in HTTP/2 streams . - CVE-2019-12418: Fixed a local privilege escalation by manipulating the RMI registry . - CVE-2019-17563: Fixed a session fixation attack when using FORM authentication . - CVE-2019-17569: Fixed a regression in the handling of Transfer-Encoding headers that would have allowed HTTP Request Smuggling . - CVE-2020-1935: Fixed an HTTP Request Smuggling issue . - CVE-2020-1938: Fixed a file contents disclosure vulnerability .

Platform:
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP4
Product:
tomcat
Reference:
SUSE-SU-2020:0632-1
CVE-2019-10072
CVE-2019-12418
CVE-2019-17563
CVE-2019-17569
CVE-2020-1935
CVE-2020-1938
CVE    6
CVE-2019-17569
CVE-2020-1935
CVE-2020-1938
CVE-2019-10072
...

© SecPod Technologies