RHEL 7 : tomcat (RHSA-2017:1809)

Medium Nessus Plugin ID 102012


The remote Red Hat host is missing one or more security updates.


An update for tomcat is now available for Red Hat Enterprise Linux 7.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies.

Security Fix(es) :

* A vulnerability was discovered in the error page mechanism in Tomcat's DefaultServlet implementation. A crafted HTTP request could cause undesired side effects, possibly including the removal or replacement of the custom error page. (CVE-2017-5664)

* A vulnerability was discovered in Tomcat. When running an untrusted application under a SecurityManager it was possible, under some circumstances, for that application to retain references to the request or response objects and thereby access and/or modify information associated with another web application. (CVE-2017-5648)


Update the affected packages.

See Also




Plugin Details

Severity: Medium

ID: 102012

File Name: redhat-RHSA-2017-1809.nasl

Version: $Revision: 3.7 $

Type: local

Agent: unix

Published: 2017/07/27

Modified: 2018/01/25

Dependencies: 12634

Risk Information

Risk Factor: Medium


Base Score: 6.4

Temporal Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

Temporal Vector: CVSS2#E:POC/RL:OF/RC:ND


Base Score: 9.1

Temporal Score: 8.2

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:X

Vulnerability Information

CPE: p-cpe:/a:redhat:enterprise_linux:tomcat, p-cpe:/a:redhat:enterprise_linux:tomcat-admin-webapps, p-cpe:/a:redhat:enterprise_linux:tomcat-docs-webapp, p-cpe:/a:redhat:enterprise_linux:tomcat-el-2.2-api, p-cpe:/a:redhat:enterprise_linux:tomcat-javadoc, p-cpe:/a:redhat:enterprise_linux:tomcat-jsp-2.2-api, p-cpe:/a:redhat:enterprise_linux:tomcat-jsvc, p-cpe:/a:redhat:enterprise_linux:tomcat-lib, p-cpe:/a:redhat:enterprise_linux:tomcat-servlet-3.0-api, p-cpe:/a:redhat:enterprise_linux:tomcat-webapps, cpe:/o:redhat:enterprise_linux:7, cpe:/o:redhat:enterprise_linux:7.3

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2017/07/27

Reference Information

CVE: CVE-2017-5648, CVE-2017-5664

OSVDB: 155233, 158615

RHSA: 2017:1809