Security update for tomcat
This update for tomcat fixes the following issues: Security issues fixed: - CVE-2018-1305: Fixed late application of security constraints that can lead to resource exposure for unauthorised users (bsc#1082481). - CVE-2018-1304: Fixed incorrect handling of empty string URL in security constraints that can lead to unitended exposure of resources (bsc#1082480). - CVE-2017-15706: Fixed incorrect documentation of CGI Servlet search algorithm that may lead to misconfiguration (bsc#1078677).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for tomcat fixes the following issues: Security issues fixed: - CVE-2018-1305: Fixed late application of security constraints that can lead to resource exposure for unauthorised users (bsc#1082481). - CVE-2018-1304: Fixed incorrect handling of empty string URL in security constraints that can lead to unitended exposure of resources (bsc#1082480). - CVE-2017-15706: Fixed incorrect documentation of CGI Servlet search algorithm that may lead to misconfiguration (bsc#1078677).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1078677
- https://bugzilla.suse.com/1082480
- https://bugzilla.suse.com/1082481
- https://www.suse.com/security/cve/CVE-2017-15706
- https://www.suse.com/security/cve/CVE-2018-1304
- https://www.suse.com/security/cve/CVE-2018-1305
- https://www.suse.com/support/update/announcement/2018/suse-su-20180817-1/