Upstream information

CVE-2016-0762 at MITRE

Description

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

SUSE information

CVSS v2 Scores
  SUSE
Base Score 5.10
Vector AV:N/AC:H/Au:N/C:P/I:P/A:P
Access Vector Network
Access Complexity High
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial

This issue is currently rated as having moderate severity.

SUSE Bugzilla entry: 1007854 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Point of Sale 11 SP3
  • tomcat6 >= 6.0.53-0.56.1
  • tomcat6-admin-webapps >= 6.0.53-0.56.1
  • tomcat6-docs-webapp >= 6.0.53-0.56.1
  • tomcat6-javadoc >= 6.0.53-0.56.1
  • tomcat6-jsp-2_1-api >= 6.0.53-0.56.1
  • tomcat6-lib >= 6.0.53-0.56.1
  • tomcat6-servlet-2_5-api >= 6.0.53-0.56.1
  • tomcat6-webapps >= 6.0.53-0.56.1
Patchnames:
sleposp3-tomcat6-13162
SUSE Linux Enterprise Server 11 SP3-LTSS
  • tomcat6 >= 6.0.53-0.56.1
  • tomcat6-admin-webapps >= 6.0.53-0.56.1
  • tomcat6-docs-webapp >= 6.0.53-0.56.1
  • tomcat6-javadoc >= 6.0.53-0.56.1
  • tomcat6-jsp-2_1-api >= 6.0.53-0.56.1
  • tomcat6-lib >= 6.0.53-0.56.1
  • tomcat6-servlet-2_5-api >= 6.0.53-0.56.1
  • tomcat6-webapps >= 6.0.53-0.56.1
Patchnames:
slessp3-tomcat6-13162
SUSE Linux Enterprise Server 11 SP4
  • tomcat6 >= 6.0.53-0.56.1
  • tomcat6-admin-webapps >= 6.0.53-0.56.1
  • tomcat6-docs-webapp >= 6.0.53-0.56.1
  • tomcat6-javadoc >= 6.0.53-0.56.1
  • tomcat6-jsp-2_1-api >= 6.0.53-0.56.1
  • tomcat6-lib >= 6.0.53-0.56.1
  • tomcat6-servlet-2_5-api >= 6.0.53-0.56.1
  • tomcat6-webapps >= 6.0.53-0.56.1
Patchnames:
slessp4-tomcat6-13162
SUSE Linux Enterprise Server 12 SP1
  • tomcat >= 8.0.32-10.13.2
  • tomcat-admin-webapps >= 8.0.32-10.13.2
  • tomcat-docs-webapp >= 8.0.32-10.13.2
  • tomcat-el-3_0-api >= 8.0.32-10.13.2
  • tomcat-javadoc >= 8.0.32-10.13.2
  • tomcat-jsp-2_3-api >= 8.0.32-10.13.2
  • tomcat-lib >= 8.0.32-10.13.2
  • tomcat-servlet-3_1-api >= 8.0.32-10.13.2
  • tomcat-webapps >= 8.0.32-10.13.2
Patchnames:
SUSE-SLE-SERVER-12-SP1-2016-1791
SUSE Linux Enterprise Server 12 SP2
  • tomcat >= 8.0.36-17.1
  • tomcat-admin-webapps >= 8.0.36-17.1
  • tomcat-docs-webapp >= 8.0.36-17.1
  • tomcat-el-3_0-api >= 8.0.36-17.1
  • tomcat-javadoc >= 8.0.36-17.1
  • tomcat-jsp-2_3-api >= 8.0.36-17.1
  • tomcat-lib >= 8.0.36-17.1
  • tomcat-servlet-3_1-api >= 8.0.36-17.1
  • tomcat-webapps >= 8.0.36-17.1
Patchnames:
SUSE-SLE-SERVER-12-SP2-2016-1790
SUSE Linux Enterprise Server 12-LTSS
  • tomcat >= 7.0.78-7.13.4
  • tomcat-admin-webapps >= 7.0.78-7.13.4
  • tomcat-docs-webapp >= 7.0.78-7.13.4
  • tomcat-el-2_2-api >= 7.0.78-7.13.4
  • tomcat-javadoc >= 7.0.78-7.13.4
  • tomcat-jsp-2_2-api >= 7.0.78-7.13.4
  • tomcat-lib >= 7.0.78-7.13.4
  • tomcat-servlet-3_0-api >= 7.0.78-7.13.4
  • tomcat-webapps >= 7.0.78-7.13.4
Patchnames:
SUSE-SLE-SERVER-12-2017-1027
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2
  • tomcat >= 8.0.36-17.1
  • tomcat-admin-webapps >= 8.0.36-17.1
  • tomcat-docs-webapp >= 8.0.36-17.1
  • tomcat-el-3_0-api >= 8.0.36-17.1
  • tomcat-javadoc >= 8.0.36-17.1
  • tomcat-jsp-2_3-api >= 8.0.36-17.1
  • tomcat-lib >= 8.0.36-17.1
  • tomcat-servlet-3_1-api >= 8.0.36-17.1
  • tomcat-webapps >= 8.0.36-17.1
Patchnames:
SUSE-SLE-RPI-12-SP2-2016-1790
SUSE Linux Enterprise for SAP 12
  • tomcat >= 7.0.78-7.13.4
  • tomcat-admin-webapps >= 7.0.78-7.13.4
  • tomcat-docs-webapp >= 7.0.78-7.13.4
  • tomcat-el-2_2-api >= 7.0.78-7.13.4
  • tomcat-javadoc >= 7.0.78-7.13.4
  • tomcat-jsp-2_2-api >= 7.0.78-7.13.4
  • tomcat-lib >= 7.0.78-7.13.4
  • tomcat-servlet-3_0-api >= 7.0.78-7.13.4
  • tomcat-webapps >= 7.0.78-7.13.4
Patchnames:
SUSE-SLE-SAP-12-2017-1027
openSUSE Leap 42.1
  • apache-commons-dbcp >= 2.1.1-2.1
  • apache-commons-dbcp-javadoc >= 2.1.1-2.1
  • apache-commons-pool2 >= 2.4.2-2.1
  • apache-commons-pool2-javadoc >= 2.4.2-2.1
  • tomcat >= 8.0.32-11.1
  • tomcat-admin-webapps >= 8.0.32-11.1
  • tomcat-docs-webapp >= 8.0.32-11.1
  • tomcat-el-3_0-api >= 8.0.32-11.1
  • tomcat-embed >= 8.0.32-11.1
  • tomcat-javadoc >= 8.0.32-11.1
  • tomcat-jsp-2_3-api >= 8.0.32-11.1
  • tomcat-jsvc >= 8.0.32-11.1
  • tomcat-lib >= 8.0.32-11.1
  • tomcat-servlet-3_1-api >= 8.0.32-11.1
  • tomcat-webapps >= 8.0.32-11.1
Patchnames:
openSUSE-2016-1455
openSUSE Leap 42.2
  • apache-commons-dbcp >= 2.1.1-2.1
  • apache-commons-dbcp-javadoc >= 2.1.1-2.1
  • apache-commons-pool2 >= 2.4.2-2.1
  • apache-commons-pool2-javadoc >= 2.4.2-2.1
  • tomcat >= 8.0.36-4.1
  • tomcat-admin-webapps >= 8.0.36-4.1
  • tomcat-docs-webapp >= 8.0.36-4.1
  • tomcat-el-3_0-api >= 8.0.36-4.1
  • tomcat-embed >= 8.0.36-4.1
  • tomcat-javadoc >= 8.0.36-4.1
  • tomcat-jsp-2_3-api >= 8.0.36-4.1
  • tomcat-jsvc >= 8.0.36-4.1
  • tomcat-lib >= 8.0.36-4.1
  • tomcat-servlet-3_1-api >= 8.0.36-4.1
  • tomcat-webapps >= 8.0.36-4.1
Patchnames:
openSUSE-2016-1456