Security update for tomcat
This update for tomcat fixes the following issues: - CVE-2025-46701: Fixed refactor CGI servlet to access resources via WebResources (bsc#1243815). - CVE-2025-48988: Fixed limits the total number of parts in a multi-part request and limits the size of the headers provided with each part (bsc#1244656). - CVE-2025-49125: Fixed expand checks for webAppMount (bsc#1244649). Other bugfixes: - Made permissions more secure (bsc#1242722)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for tomcat fixes the following issues: - CVE-2025-46701: Fixed refactor CGI servlet to access resources via WebResources (bsc#1243815). - CVE-2025-48988: Fixed limits the total number of parts in a multi-part request and limits the size of the headers provided with each part (bsc#1244656). - CVE-2025-49125: Fixed expand checks for webAppMount (bsc#1244649). Other bugfixes: - Made permissions more secure (bsc#1242722)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1242722
- https://bugzilla.suse.com/1243815
- https://bugzilla.suse.com/1244649
- https://bugzilla.suse.com/1244656
- https://www.suse.com/security/cve/CVE-2025-46701
- https://www.suse.com/security/cve/CVE-2025-48988
- https://www.suse.com/security/cve/CVE-2025-49125
- https://www.suse.com/support/update/announcement/2025/suse-su-202502280-1/