Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:1572-1

Опубликовано: 23 апр. 2026
Источник: suse-cvrf

Описание

Security update for tomcat

This update for tomcat fixes the following issues:

Security fixes:

  • CVE-2026-24880: Request smuggling via invalid chunk extension (bsc#1261850).
  • CVE-2026-25854: Occasionally open redirect (bsc#1261851).
  • CVE-2026-29129: TLS cipher order is not preserved (bsc#1261852).
  • CVE-2026-29145: OCSP checks sometimes soft-fail even when soft-fail is disabled (bsc#1261853).
  • CVE-2026-29146,CVE-2026-34486: Fix for allowed bypass of EncryptInterceptor (bsc#1261854).
  • CVE-2026-34483: Incomplete escaping of JSON access logs (bsc#1261855).
  • CVE-2026-34487: Cloud membership for clustering component exposed the Kubernetes bearer token (bsc#1261856).
  • CVE-2026-34500: OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled (bsc#1261857).
  • CVE-2026-32990: The fix for CVE-2025-66614 was incomplete, so this CVE completes it (bsc#1258371).

Other fixes:

  • Update to Tomcat 9.0.117

Список пакетов

SUSE Linux Enterprise Server 12 SP5-LTSS
tomcat-9.0.117-3.163.2
tomcat-admin-webapps-9.0.117-3.163.2
tomcat-docs-webapp-9.0.117-3.163.2
tomcat-el-3_0-api-9.0.117-3.163.2
tomcat-javadoc-9.0.117-3.163.2
tomcat-jsp-2_3-api-9.0.117-3.163.2
tomcat-lib-9.0.117-3.163.2
tomcat-servlet-4_0-api-9.0.117-3.163.2
tomcat-webapps-9.0.117-3.163.2
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
tomcat-9.0.117-3.163.2
tomcat-admin-webapps-9.0.117-3.163.2
tomcat-docs-webapp-9.0.117-3.163.2
tomcat-el-3_0-api-9.0.117-3.163.2
tomcat-javadoc-9.0.117-3.163.2
tomcat-jsp-2_3-api-9.0.117-3.163.2
tomcat-lib-9.0.117-3.163.2
tomcat-servlet-4_0-api-9.0.117-3.163.2
tomcat-webapps-9.0.117-3.163.2

Описание

Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Older EOL versions are not affected. Tomcat did not validate that the host name provided via the SNI extension was the same as the host name provided in the HTTP host header field. If Tomcat was configured with more than one virtual host and the TLS configuration for one of those hosts did not require client certificate authentication but another one did, it was possible for a client to bypass the client certificate authentication by sending different host names in the SNI extension and the HTTP host header field. The vulnerability only applies if client certificate authentication is only enforced at the Connector. It does not apply if client certificate authentication is enforced at the web application. Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fix the issue.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-9.0.117-3.163.2
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-admin-webapps-9.0.117-3.163.2
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-docs-webapp-9.0.117-3.163.2
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-el-3_0-api-9.0.117-3.163.2

Ссылки

Описание

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M1 through 9.0.115, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other, unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.20, 10.1.52 or 9.0.116, which fix the issue.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-9.0.117-3.163.2
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-admin-webapps-9.0.117-3.163.2
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-docs-webapp-9.0.117-3.163.2
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-el-3_0-api-9.0.117-3.163.2

Ссылки

Описание

Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M23 through 9.0.115, from 8.5.30 through 8.5.100. Other, unsupported versions may also be affected Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-9.0.117-3.163.2
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-admin-webapps-9.0.117-3.163.2
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-docs-webapp-9.0.117-3.163.2
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-el-3_0-api-9.0.117-3.163.2

Ссылки

Описание

Configured cipher preference order not preserved vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115. Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-9.0.117-3.163.2
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-admin-webapps-9.0.117-3.163.2
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-docs-webapp-9.0.117-3.163.2
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-el-3_0-api-9.0.117-3.163.2

Ссылки

Описание

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13. Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.0.20, 10.1.53 and 9.0.116, which fix the issue.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-9.0.117-3.163.2
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-admin-webapps-9.0.117-3.163.2
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-docs-webapp-9.0.117-3.163.2
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-el-3_0-api-9.0.117-3.163.2

Ссылки

Описание

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-9.0.117-3.163.2
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-admin-webapps-9.0.117-3.163.2
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-docs-webapp-9.0.117-3.163.2
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-el-3_0-api-9.0.117-3.163.2

Ссылки

Описание

Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115. Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-9.0.117-3.163.2
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-admin-webapps-9.0.117-3.163.2
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-docs-webapp-9.0.117-3.163.2
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-el-3_0-api-9.0.117-3.163.2

Ссылки

Описание

Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117 , which fix the issue.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-9.0.117-3.163.2
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-admin-webapps-9.0.117-3.163.2
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-docs-webapp-9.0.117-3.163.2
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-el-3_0-api-9.0.117-3.163.2

Ссылки

Описание

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-9.0.117-3.163.2
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-admin-webapps-9.0.117-3.163.2
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-docs-webapp-9.0.117-3.163.2
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-el-3_0-api-9.0.117-3.163.2

Ссылки

Описание

Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-9.0.117-3.163.2
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-admin-webapps-9.0.117-3.163.2
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-docs-webapp-9.0.117-3.163.2
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-el-3_0-api-9.0.117-3.163.2

Ссылки

Описание

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fixes the issue.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-9.0.117-3.163.2
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-admin-webapps-9.0.117-3.163.2
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-docs-webapp-9.0.117-3.163.2
SUSE Linux Enterprise Server 12 SP5-LTSS:tomcat-el-3_0-api-9.0.117-3.163.2

Ссылки