{"id":"SUSE-SU-2020:14375-1","summary":"Security update for tomcat6","details":"This update for tomcat6 fixes the following issues:\n\nCVE-2020-9484 (bsc#1171928)\nApache Tomcat Remote Code Execution via session persistence\n\nIf an attacker was able to control the contents and name of a file on a\nserver configured to use the PersistenceManager, then the attacker could\nhave triggered a remote code execution via deserialization of the file under\ntheir control.\n\nCVE-2019-12418 (bsc#1159723)\nLocal privilege escalation by manipulating the RMI registry and performing a man-in-the-middle attack\n\nWhen Tomcat is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files was able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface.\nThe attacker could then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.\n\nCVE-2019-0221 (bsc#1136085)\nThe SSI printenv command echoed user provided data without escaping, which\nmade it vulnerable to XSS.\n\n","modified":"2026-03-11T07:12:40.146191Z","published":"2020-05-22T13:01:48Z","related":["CVE-2019-0221","CVE-2019-12418","CVE-2020-9484"],"upstream":["CVE-2019-0221","CVE-2019-12418","CVE-2020-9484"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2020/suse-su-202014375-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1136085"},{"type":"REPORT","url":"https://bugzilla.suse.com/1159723"},{"type":"REPORT","url":"https://bugzilla.suse.com/1171928"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-0221"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-12418"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-9484"}],"affected":[{"package":{"name":"tomcat6","ecosystem":"SUSE:Linux Enterprise Point of Sale 11 SP3","purl":"pkg:rpm/suse/tomcat6&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.53-0.57.16.1"}]}],"ecosystem_specific":{"binaries":[{"tomcat6-webapps":"6.0.53-0.57.16.1","tomcat6":"6.0.53-0.57.16.1","tomcat6-admin-webapps":"6.0.53-0.57.16.1","tomcat6-docs-webapp":"6.0.53-0.57.16.1","tomcat6-javadoc":"6.0.53-0.57.16.1","tomcat6-jsp-2_1-api":"6.0.53-0.57.16.1","tomcat6-lib":"6.0.53-0.57.16.1","tomcat6-servlet-2_5-api":"6.0.53-0.57.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:14375-1.json"}},{"package":{"name":"tomcat6","ecosystem":"SUSE:Linux Enterprise Server 11 SP4-LTSS","purl":"pkg:rpm/suse/tomcat6&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.53-0.57.16.1"}]}],"ecosystem_specific":{"binaries":[{"tomcat6-jsp-2_1-api":"6.0.53-0.57.16.1","tomcat6-lib":"6.0.53-0.57.16.1","tomcat6-servlet-2_5-api":"6.0.53-0.57.16.1","tomcat6-webapps":"6.0.53-0.57.16.1","tomcat6":"6.0.53-0.57.16.1","tomcat6-admin-webapps":"6.0.53-0.57.16.1","tomcat6-docs-webapp":"6.0.53-0.57.16.1","tomcat6-javadoc":"6.0.53-0.57.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:14375-1.json"}}],"schema_version":"1.7.5"}