Security update for tomcat
This update for tomcat to version 9.0.30 fixes the following issues: Security issue fixed: - CVE-2019-12418: Fixed a local privilege escalation through by manipulating the RMI registry and performing a man-in-the-middle attack (bsc#1159723). - CVE-2019-17563: Fixed a session fixation attack when using FORM authentication (bsc#1159729).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for tomcat to version 9.0.30 fixes the following issues: Security issue fixed: - CVE-2019-12418: Fixed a local privilege escalation through by manipulating the RMI registry and performing a man-in-the-middle attack (bsc#1159723). - CVE-2019-17563: Fixed a session fixation attack when using FORM authentication (bsc#1159729).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1139924
- https://bugzilla.suse.com/1159723
- https://bugzilla.suse.com/1159729
- https://www.suse.com/security/cve/CVE-2019-10072
- https://www.suse.com/security/cve/CVE-2019-12418
- https://www.suse.com/security/cve/CVE-2019-17563
- https://www.suse.com/support/update/announcement/2020/suse-su-20200029-1/