Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:02214-1

Опубликовано: 03 июл. 2025
Источник: suse-cvrf

Описание

Security update for tomcat

This update for tomcat fixes the following issues:

  • CVE-2025-46701: Refactored CGI servlet to access resources via WebResources (bsc#1243815).
  • CVE-2025-48988: Limited the total number of parts in a multi-part request and limits the size of the headers provided with each part (bsc#1244656).
  • CVE-2025-49125: Expand checks for webAppMount (bsc#1244649).

Список пакетов

SUSE Linux Enterprise Server 12 SP5-LTSS
tomcat-9.0.36-3.145.1
tomcat-admin-webapps-9.0.36-3.145.1
tomcat-docs-webapp-9.0.36-3.145.1
tomcat-el-3_0-api-9.0.36-3.145.1
tomcat-javadoc-9.0.36-3.145.1
tomcat-jsp-2_3-api-9.0.36-3.145.1
tomcat-lib-9.0.36-3.145.1
tomcat-servlet-4_0-api-9.0.36-3.145.1
tomcat-webapps-9.0.36-3.145.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
tomcat-9.0.36-3.145.1
tomcat-admin-webapps-9.0.36-3.145.1
tomcat-docs-webapp-9.0.36-3.145.1
tomcat-el-3_0-api-9.0.36-3.145.1
tomcat-javadoc-9.0.36-3.145.1
tomcat-jsp-2_3-api-9.0.36-3.145.1
tomcat-lib-9.0.36-3.145.1
tomcat-servlet-4_0-api-9.0.36-3.145.1
tomcat-webapps-9.0.36-3.145.1

Описание

Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that apply to the pathInfo component of a URI mapped to the CGI servlet. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.6, from 10.1.0-M1 through 10.1.40, from 9.0.0.M1 through 9.0.104. Users are recommended to upgrade to version 11.0.7, 10.1.41 or 9.0.105, which fixes the issue.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-9.0.36-3.145.1
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-admin-webapps-9.0.36-3.145.1
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-docs-webapp-9.0.36-3.145.1
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-el-3_0-api-9.0.36-3.145.1

Ссылки

Описание

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-9.0.36-3.145.1
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-admin-webapps-9.0.36-3.145.1
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-docs-webapp-9.0.36-3.145.1
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-el-3_0-api-9.0.36-3.145.1

Ссылки

Описание

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-9.0.36-3.145.1
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-admin-webapps-9.0.36-3.145.1
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-docs-webapp-9.0.36-3.145.1
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-el-3_0-api-9.0.36-3.145.1

Ссылки