SUSE-SU-2017:3059-1

Advisory lineage Upstream: 5 Downstream: 0
Published: 23 Nov 2017, 16:16
Last modified:04 Feb 2026, 03:47

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

23 Nov 2017, 16:16
Published
Vulnerability first disclosed
04 Feb 2026, 03:47
Last Modified
Vulnerability information updated

Description

Security update for tomcat Apache Tomcat was updated to 7.0.82 adding features, fixing bugs and security issues. This is another bugfix release, for full details see: https://tomcat.apache.org/tomcat-7.0-doc/changelog.html Fixed security issues: - CVE-2017-5664: A problem in handling error pages was fixed, to avoid potential file overwrites during error page handling. (bsc#1042910). - CVE-2017-7674: A CORS Filter issue could lead to client and server side cache poisoning (bsc#1053352) - CVE-2017-12617: A remote code execution possibility via JSP Upload was fixed (bsc#1059554) - CVE-2017-12616: An information disclosure when using VirtualDirContext was fixed (bsc#1059551) - CVE-2017-12615: A Remote Code Execution via JSP Upload was fixed (bsc#1059554) Non-security issues fixed: - Fix tomcat-digest classpath error (bsc#977410)

Affected Systems

  • susetomcat&distro=SUSE Linux Enterprise Server 12-LTSS

    < 7.0.82-7.16.1

References (11)