SuSE Security Update: Security update for Tomcat 5 (tomcat5-6841)

medium Nessus Plugin ID 45472

Language:

Synopsis

The remote SuSE system is missing the security patch tomcat5-6841

Description

This update of tomcat5/6 fixes:



CVE-2009-2693: CVSS v2 Base Score: 5.8 CVE-2009-2902: CVSS v2 Base Score: 4.3 Directory traversal vulnerability allowed remote attackers to create or overwrite arbitrary files/dirs with a specially crafted WAR file.
CVE-2009-2901: CVSS v2 Base Score: 4.3 When autoDeploy is enabled the autodeployment process deployed appBase files that remain from a failed undeploy, which might allow remote attackers to bypass intended authentication requirements via HTTP requests.

Solution

Install the security patch tomcat5-6841

Plugin Details

Severity: Medium

ID: 45472

File Name: suse_tomcat5-6841.nasl

Version: 1.9

Type: local

Agent: unix

Published: 4/9/2010

Updated: 1/14/2021

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.5

CVSS v2

Risk Factor: Medium

Base Score: 5.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:P

CVSS Score Source: CVE-2009-2693

Vulnerability Information

CPE: p-cpe:/a:novell:suse_linux:tomcat5-webapps, p-cpe:/a:novell:suse_linux:tomcat5, p-cpe:/a:novell:suse_linux:tomcat5-admin-webapps, cpe:/o:novell:suse_linux:10

Required KB Items: Host/SuSE/rpm-list

Reference Information

CVE: CVE-2009-2693, CVE-2009-2901, CVE-2009-2902

CWE: 22, 264