Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2020:14375-1

Опубликовано: 22 мая 2020
Источник: suse-cvrf

Описание

Security update for tomcat6

This update for tomcat6 fixes the following issues:

CVE-2020-9484 (bsc#1171928) Apache Tomcat Remote Code Execution via session persistence

If an attacker was able to control the contents and name of a file on a server configured to use the PersistenceManager, then the attacker could have triggered a remote code execution via deserialization of the file under their control.

CVE-2019-12418 (bsc#1159723) Local privilege escalation by manipulating the RMI registry and performing a man-in-the-middle attack

When Tomcat is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files was able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker could then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.

CVE-2019-0221 (bsc#1136085) The SSI printenv command echoed user provided data without escaping, which made it vulnerable to XSS.

Список пакетов

SUSE Linux Enterprise Point of Sale 11 SP3
tomcat6-6.0.53-0.57.16.1
tomcat6-admin-webapps-6.0.53-0.57.16.1
tomcat6-docs-webapp-6.0.53-0.57.16.1
tomcat6-javadoc-6.0.53-0.57.16.1
tomcat6-jsp-2_1-api-6.0.53-0.57.16.1
tomcat6-lib-6.0.53-0.57.16.1
tomcat6-servlet-2_5-api-6.0.53-0.57.16.1
tomcat6-webapps-6.0.53-0.57.16.1
SUSE Linux Enterprise Server 11 SP4-LTSS
tomcat6-6.0.53-0.57.16.1
tomcat6-admin-webapps-6.0.53-0.57.16.1
tomcat6-docs-webapp-6.0.53-0.57.16.1
tomcat6-javadoc-6.0.53-0.57.16.1
tomcat6-jsp-2_1-api-6.0.53-0.57.16.1
tomcat6-lib-6.0.53-0.57.16.1
tomcat6-servlet-2_5-api-6.0.53-0.57.16.1
tomcat6-webapps-6.0.53-0.57.16.1

Описание

The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.


Затронутые продукты
SUSE Linux Enterprise Point of Sale 11 SP3:tomcat6-6.0.53-0.57.16.1
SUSE Linux Enterprise Point of Sale 11 SP3:tomcat6-admin-webapps-6.0.53-0.57.16.1
SUSE Linux Enterprise Point of Sale 11 SP3:tomcat6-docs-webapp-6.0.53-0.57.16.1
SUSE Linux Enterprise Point of Sale 11 SP3:tomcat6-javadoc-6.0.53-0.57.16.1

Ссылки

Описание

When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.


Затронутые продукты
SUSE Linux Enterprise Point of Sale 11 SP3:tomcat6-6.0.53-0.57.16.1
SUSE Linux Enterprise Point of Sale 11 SP3:tomcat6-admin-webapps-6.0.53-0.57.16.1
SUSE Linux Enterprise Point of Sale 11 SP3:tomcat6-docs-webapp-6.0.53-0.57.16.1
SUSE Linux Enterprise Point of Sale 11 SP3:tomcat6-javadoc-6.0.53-0.57.16.1

Ссылки

Описание

When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is configured with sessionAttributeValueClassNameFilter="null" (the default unless a SecurityManager is used) or a sufficiently lax filter to allow the attacker provided object to be deserialized; and d) the attacker knows the relative file path from the storage location used by FileStore to the file the attacker has control over; then, using a specifically crafted request, the attacker will be able to trigger remote code execution via deserialization of the file under their control. Note that all of conditions a) to d) must be true for the attack to succeed.


Затронутые продукты
SUSE Linux Enterprise Point of Sale 11 SP3:tomcat6-6.0.53-0.57.16.1
SUSE Linux Enterprise Point of Sale 11 SP3:tomcat6-admin-webapps-6.0.53-0.57.16.1
SUSE Linux Enterprise Point of Sale 11 SP3:tomcat6-docs-webapp-6.0.53-0.57.16.1
SUSE Linux Enterprise Point of Sale 11 SP3:tomcat6-javadoc-6.0.53-0.57.16.1

Ссылки