Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2020:1498-1

Опубликовано: 28 мая 2020
Источник: suse-cvrf

Описание

Security update for tomcat

This update for tomcat fixes the following issues:

CVE-2020-9484 (bsc#1171928) Apache Tomcat Remote Code Execution via session persistence

If an attacker was able to control the contents and name of a file on a server configured to use the PersistenceManager, then the attacker could have triggered a remote code execution via deserialization of the file under their control.

CVE-2019-12418 (bsc#1159723) Local privilege escalation by manipulating the RMI registry and performing a man-in-the-middle attack

When Tomcat is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files was able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker could then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.

CVE-2019-0221 (bsc#1136085) The SSI printenv command echoed user provided data without escaping, which made it vulnerable to XSS.

CVE-2019-17563 (bsc#1159729) When using FORM authentication there was a narrow window where an attacker could perform a session fixation attack.

CVE-2019-17569 (bsc#1164825) Invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header.

Список пакетов

HPE Helion OpenStack 8
tomcat-8.0.53-29.27.1
tomcat-admin-webapps-8.0.53-29.27.1
tomcat-docs-webapp-8.0.53-29.27.1
tomcat-el-3_0-api-8.0.53-29.27.1
tomcat-javadoc-8.0.53-29.27.1
tomcat-jsp-2_3-api-8.0.53-29.27.1
tomcat-lib-8.0.53-29.27.1
tomcat-servlet-3_1-api-8.0.53-29.27.1
tomcat-webapps-8.0.53-29.27.1
SUSE Enterprise Storage 5
tomcat-8.0.53-29.27.1
tomcat-admin-webapps-8.0.53-29.27.1
tomcat-docs-webapp-8.0.53-29.27.1
tomcat-el-3_0-api-8.0.53-29.27.1
tomcat-javadoc-8.0.53-29.27.1
tomcat-jsp-2_3-api-8.0.53-29.27.1
tomcat-lib-8.0.53-29.27.1
tomcat-servlet-3_1-api-8.0.53-29.27.1
tomcat-webapps-8.0.53-29.27.1
SUSE Linux Enterprise Server 12 SP2-BCL
tomcat-8.0.53-29.27.1
tomcat-admin-webapps-8.0.53-29.27.1
tomcat-docs-webapp-8.0.53-29.27.1
tomcat-el-3_0-api-8.0.53-29.27.1
tomcat-javadoc-8.0.53-29.27.1
tomcat-jsp-2_3-api-8.0.53-29.27.1
tomcat-lib-8.0.53-29.27.1
tomcat-servlet-3_1-api-8.0.53-29.27.1
tomcat-webapps-8.0.53-29.27.1
SUSE Linux Enterprise Server 12 SP2-LTSS
tomcat-8.0.53-29.27.1
tomcat-admin-webapps-8.0.53-29.27.1
tomcat-docs-webapp-8.0.53-29.27.1
tomcat-el-3_0-api-8.0.53-29.27.1
tomcat-javadoc-8.0.53-29.27.1
tomcat-jsp-2_3-api-8.0.53-29.27.1
tomcat-lib-8.0.53-29.27.1
tomcat-servlet-3_1-api-8.0.53-29.27.1
tomcat-webapps-8.0.53-29.27.1
SUSE Linux Enterprise Server 12 SP3-BCL
tomcat-8.0.53-29.27.1
tomcat-admin-webapps-8.0.53-29.27.1
tomcat-docs-webapp-8.0.53-29.27.1
tomcat-el-3_0-api-8.0.53-29.27.1
tomcat-javadoc-8.0.53-29.27.1
tomcat-jsp-2_3-api-8.0.53-29.27.1
tomcat-lib-8.0.53-29.27.1
tomcat-servlet-3_1-api-8.0.53-29.27.1
tomcat-webapps-8.0.53-29.27.1
SUSE Linux Enterprise Server 12 SP3-LTSS
tomcat-8.0.53-29.27.1
tomcat-admin-webapps-8.0.53-29.27.1
tomcat-docs-webapp-8.0.53-29.27.1
tomcat-el-3_0-api-8.0.53-29.27.1
tomcat-javadoc-8.0.53-29.27.1
tomcat-jsp-2_3-api-8.0.53-29.27.1
tomcat-lib-8.0.53-29.27.1
tomcat-servlet-3_1-api-8.0.53-29.27.1
tomcat-webapps-8.0.53-29.27.1
SUSE Linux Enterprise Server for SAP Applications 12 SP2
tomcat-8.0.53-29.27.1
tomcat-admin-webapps-8.0.53-29.27.1
tomcat-docs-webapp-8.0.53-29.27.1
tomcat-el-3_0-api-8.0.53-29.27.1
tomcat-javadoc-8.0.53-29.27.1
tomcat-jsp-2_3-api-8.0.53-29.27.1
tomcat-lib-8.0.53-29.27.1
tomcat-servlet-3_1-api-8.0.53-29.27.1
tomcat-webapps-8.0.53-29.27.1
SUSE Linux Enterprise Server for SAP Applications 12 SP3
tomcat-8.0.53-29.27.1
tomcat-admin-webapps-8.0.53-29.27.1
tomcat-docs-webapp-8.0.53-29.27.1
tomcat-el-3_0-api-8.0.53-29.27.1
tomcat-javadoc-8.0.53-29.27.1
tomcat-jsp-2_3-api-8.0.53-29.27.1
tomcat-lib-8.0.53-29.27.1
tomcat-servlet-3_1-api-8.0.53-29.27.1
tomcat-webapps-8.0.53-29.27.1
SUSE OpenStack Cloud 7
tomcat-8.0.53-29.27.1
tomcat-admin-webapps-8.0.53-29.27.1
tomcat-docs-webapp-8.0.53-29.27.1
tomcat-el-3_0-api-8.0.53-29.27.1
tomcat-javadoc-8.0.53-29.27.1
tomcat-jsp-2_3-api-8.0.53-29.27.1
tomcat-lib-8.0.53-29.27.1
tomcat-servlet-3_1-api-8.0.53-29.27.1
tomcat-webapps-8.0.53-29.27.1
SUSE OpenStack Cloud 8
tomcat-8.0.53-29.27.1
tomcat-admin-webapps-8.0.53-29.27.1
tomcat-docs-webapp-8.0.53-29.27.1
tomcat-el-3_0-api-8.0.53-29.27.1
tomcat-javadoc-8.0.53-29.27.1
tomcat-jsp-2_3-api-8.0.53-29.27.1
tomcat-lib-8.0.53-29.27.1
tomcat-servlet-3_1-api-8.0.53-29.27.1
tomcat-webapps-8.0.53-29.27.1
SUSE OpenStack Cloud Crowbar 8
tomcat-8.0.53-29.27.1
tomcat-admin-webapps-8.0.53-29.27.1
tomcat-docs-webapp-8.0.53-29.27.1
tomcat-el-3_0-api-8.0.53-29.27.1
tomcat-javadoc-8.0.53-29.27.1
tomcat-jsp-2_3-api-8.0.53-29.27.1
tomcat-lib-8.0.53-29.27.1
tomcat-servlet-3_1-api-8.0.53-29.27.1
tomcat-webapps-8.0.53-29.27.1

Описание

The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.


Затронутые продукты
HPE Helion OpenStack 8:tomcat-8.0.53-29.27.1
HPE Helion OpenStack 8:tomcat-admin-webapps-8.0.53-29.27.1
HPE Helion OpenStack 8:tomcat-docs-webapp-8.0.53-29.27.1
HPE Helion OpenStack 8:tomcat-el-3_0-api-8.0.53-29.27.1

Ссылки

Описание

When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.


Затронутые продукты
HPE Helion OpenStack 8:tomcat-8.0.53-29.27.1
HPE Helion OpenStack 8:tomcat-admin-webapps-8.0.53-29.27.1
HPE Helion OpenStack 8:tomcat-docs-webapp-8.0.53-29.27.1
HPE Helion OpenStack 8:tomcat-el-3_0-api-8.0.53-29.27.1

Ссылки

Описание

When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability.


Затронутые продукты
HPE Helion OpenStack 8:tomcat-8.0.53-29.27.1
HPE Helion OpenStack 8:tomcat-admin-webapps-8.0.53-29.27.1
HPE Helion OpenStack 8:tomcat-docs-webapp-8.0.53-29.27.1
HPE Helion OpenStack 8:tomcat-el-3_0-api-8.0.53-29.27.1

Ссылки

Описание

The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.


Затронутые продукты
HPE Helion OpenStack 8:tomcat-8.0.53-29.27.1
HPE Helion OpenStack 8:tomcat-admin-webapps-8.0.53-29.27.1
HPE Helion OpenStack 8:tomcat-docs-webapp-8.0.53-29.27.1
HPE Helion OpenStack 8:tomcat-el-3_0-api-8.0.53-29.27.1

Ссылки

Описание

When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is configured with sessionAttributeValueClassNameFilter="null" (the default unless a SecurityManager is used) or a sufficiently lax filter to allow the attacker provided object to be deserialized; and d) the attacker knows the relative file path from the storage location used by FileStore to the file the attacker has control over; then, using a specifically crafted request, the attacker will be able to trigger remote code execution via deserialization of the file under their control. Note that all of conditions a) to d) must be true for the attack to succeed.


Затронутые продукты
HPE Helion OpenStack 8:tomcat-8.0.53-29.27.1
HPE Helion OpenStack 8:tomcat-admin-webapps-8.0.53-29.27.1
HPE Helion OpenStack 8:tomcat-docs-webapp-8.0.53-29.27.1
HPE Helion OpenStack 8:tomcat-el-3_0-api-8.0.53-29.27.1

Ссылки
Уязвимость SUSE-SU-2020:1498-1