Security update for tomcat
This update for tomcat fixes the following issues: - CVE-2025-55752: Fixed directory traversal via rewrite with possible RCE if PUT is enabled (bsc#1252753) - CVE-2025-55754: Fixed improper neutralization of escape, meta, or control sequences vulnerability (bsc#1252905) - CVE-2025-61795: Fixed denial of service due to temporary copies during the processing of multipart upload (bsc#1252756)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for tomcat fixes the following issues: - CVE-2025-55752: Fixed directory traversal via rewrite with possible RCE if PUT is enabled (bsc#1252753) - CVE-2025-55754: Fixed improper neutralization of escape, meta, or control sequences vulnerability (bsc#1252905) - CVE-2025-61795: Fixed denial of service due to temporary copies during the processing of multipart upload (bsc#1252756)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1252753
- https://bugzilla.suse.com/1252756
- https://bugzilla.suse.com/1252905
- https://www.suse.com/security/cve/CVE-2025-55752
- https://www.suse.com/security/cve/CVE-2025-55754
- https://www.suse.com/security/cve/CVE-2025-61795
- https://www.suse.com/support/update/announcement/2025/suse-su-20254184-1/