Security update for tomcat
This update for tomcat to version 9.0.30 fixes the following issues: Security issue fixed: - CVE-2019-12418: Fixed a local privilege escalation by manipulating the RMI registry (bsc#1159723). - CVE-2019-17563: Fixed a session fixation attack when using FORM authentication (bsc#1159729). Non-security issue fixed: - Fixed a problem during startup, related to changes in Java 9+ APIs (bsc#1161025).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for tomcat to version 9.0.30 fixes the following issues: Security issue fixed: - CVE-2019-12418: Fixed a local privilege escalation by manipulating the RMI registry (bsc#1159723). - CVE-2019-17563: Fixed a session fixation attack when using FORM authentication (bsc#1159729). Non-security issue fixed: - Fixed a problem during startup, related to changes in Java 9+ APIs (bsc#1161025).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1139924
- https://bugzilla.suse.com/1159723
- https://bugzilla.suse.com/1159729
- https://bugzilla.suse.com/1161025
- https://www.suse.com/security/cve/CVE-2019-10072
- https://www.suse.com/security/cve/CVE-2019-12418
- https://www.suse.com/security/cve/CVE-2019-17563
- https://www.suse.com/support/update/announcement/2020/suse-su-20200226-1/