FlawAtlas
Search the atlas
SUSE-SU-2021:0040-1 Not scored

Security update for tomcat

This update for tomcat fixes the following issues: Security issues fixed: - CVE-2020-13943: Fixed a HTTP/2 Request mix-up (bsc#1177582). - CVE-2020-17527: Fixed a HTTP/2 request header mix-up (bsc#1179602). Non-security issue fixed: - Removed tomcat-9.0.init and /usr/lib/tmpfiles.d/tomcat.conf from package. They're not used anymore becuse of systemd (bsc#1178396). - Fixed 'tomcat-servlet-4_0-api' package alternatives to use and keep a symlink for compatibility (bsc#1092163). - Don't give write permissions for the tomcat group on files and directories where it's not needed (bsc#1172562).

Exploit probability Not scored
Published January 7, 2021
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise High Performance Computing 15-ESPOS tomcat
SUSE:Linux Enterprise High Performance Computing 15-LTSS tomcat
SUSE:Linux Enterprise Server 15-LTSS tomcat
SUSE:Linux Enterprise Server for SAP Applications 15 tomcat

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2021:0040-1

This update for tomcat fixes the following issues: Security issues fixed: - CVE-2020-13943: Fixed a HTTP/2 Request mix-up (bsc#1177582). - CVE-2020-17527: Fixed a HTTP/2 request header mix-up (bsc#1179602). Non-security issue fixed: - Removed tomcat-9.0.init and /usr/lib/tmpfiles.d/tomcat.conf from package. They're not used anymore becuse of systemd (bsc#1178396). - Fixed 'tomcat-servlet-4_0-api' package alternatives to use and keep a symlink for compatibility (bsc#1092163). - Don't give write permissions for the tomcat group on files and directories where it's not needed (bsc#1172562).

View original source

05 / REFERENCES

Further evidence