Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2020:1365-1

Опубликовано: 21 мая 2020
Источник: suse-cvrf

Описание

Security update for tomcat

This update for tomcat fixes the following issues:

  • CVE-2020-9484 (bsc#1171928) Apache Tomcat Remote Code Execution via session persistence

    If an attacker was able to control the contents and name of a file on a server configured to use the PersistenceManager, then the attacker could have triggered a remote code execution via deserialization of the file under their control.

Список пакетов

SUSE Linux Enterprise Server 12 SP4
tomcat-9.0.35-3.32.1
tomcat-admin-webapps-9.0.35-3.32.1
tomcat-docs-webapp-9.0.35-3.32.1
tomcat-el-3_0-api-9.0.35-3.32.1
tomcat-javadoc-9.0.35-3.32.1
tomcat-jsp-2_3-api-9.0.35-3.32.1
tomcat-lib-9.0.35-3.32.1
tomcat-servlet-4_0-api-9.0.35-3.32.1
tomcat-webapps-9.0.35-3.32.1
SUSE Linux Enterprise Server 12 SP5
tomcat-9.0.35-3.32.1
tomcat-admin-webapps-9.0.35-3.32.1
tomcat-docs-webapp-9.0.35-3.32.1
tomcat-el-3_0-api-9.0.35-3.32.1
tomcat-javadoc-9.0.35-3.32.1
tomcat-jsp-2_3-api-9.0.35-3.32.1
tomcat-lib-9.0.35-3.32.1
tomcat-servlet-4_0-api-9.0.35-3.32.1
tomcat-webapps-9.0.35-3.32.1
SUSE Linux Enterprise Server for SAP Applications 12 SP4
tomcat-9.0.35-3.32.1
tomcat-admin-webapps-9.0.35-3.32.1
tomcat-docs-webapp-9.0.35-3.32.1
tomcat-el-3_0-api-9.0.35-3.32.1
tomcat-javadoc-9.0.35-3.32.1
tomcat-jsp-2_3-api-9.0.35-3.32.1
tomcat-lib-9.0.35-3.32.1
tomcat-servlet-4_0-api-9.0.35-3.32.1
tomcat-webapps-9.0.35-3.32.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5
tomcat-9.0.35-3.32.1
tomcat-admin-webapps-9.0.35-3.32.1
tomcat-docs-webapp-9.0.35-3.32.1
tomcat-el-3_0-api-9.0.35-3.32.1
tomcat-javadoc-9.0.35-3.32.1
tomcat-jsp-2_3-api-9.0.35-3.32.1
tomcat-lib-9.0.35-3.32.1
tomcat-servlet-4_0-api-9.0.35-3.32.1
tomcat-webapps-9.0.35-3.32.1

Описание

When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is configured with sessionAttributeValueClassNameFilter="null" (the default unless a SecurityManager is used) or a sufficiently lax filter to allow the attacker provided object to be deserialized; and d) the attacker knows the relative file path from the storage location used by FileStore to the file the attacker has control over; then, using a specifically crafted request, the attacker will be able to trigger remote code execution via deserialization of the file under their control. Note that all of conditions a) to d) must be true for the attack to succeed.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP4:tomcat-9.0.35-3.32.1
SUSE Linux Enterprise Server 12 SP4:tomcat-admin-webapps-9.0.35-3.32.1
SUSE Linux Enterprise Server 12 SP4:tomcat-docs-webapp-9.0.35-3.32.1
SUSE Linux Enterprise Server 12 SP4:tomcat-el-3_0-api-9.0.35-3.32.1

Ссылки