SUSE SLES15: tomcat10 / tomcat10-admin-webapps / tomcat10-el-5_0-api / etc (SUSE-SU-2026:4119-1)

medium Nessus Plugin ID 345835

Language:

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLES15 / SLES_SAP15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:4119-1 advisory.

- CVE-2026-65182: Apache Tomcat: Bypass longest prefix security constraint (bsc#1276893).
- CVE-2026-65183: Apache Tomcat: TOCTOU when setting specific permissions for Unix Domain Sockets (bsc#1276894).
- CVE-2026-65637: Apache Tomcat: HTTP/2 no-authority bypass of strict SNI validation - fix incomplete (bsc#1276895).
- CVE-2026-65905: Apache Tomcat: Limited replay attack possible with DIGEST authentication (bsc#1276896).
- CVE-2026-65927: Apache Tomcat: RewriteValve [N] restarts at the second rule and may bypass access control (bsc#1276897).
- CVE-2026-66299: memory exhaustion via maliciously slow clients due to the WebSocket chat example providing an unbounded buffer for undelivered messages (bsc#1273150).
- CVE-2026-66422: Apache Tomcat: Servlet role references can bypass declarative role constraints (bsc#1276898).
- CVE-2026-68525: Apache Tomcat: Redirect after FORM auth may bypass method specific constraints (bsc#1276899).
- CVE-2026-68569: Apache Tomcat: Principal lookup can fail open in some cases (bsc#1276900).
- CVE-2026-68763: Apache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset (bsc#1276901).
- CVE-2026-73180: Apache Tomcat: Authenticated WebSocket session survives end of HTTP session (bsc#1276902).

Changes for tomcat10:

- Updated to version 10.1.59

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1273150

https://bugzilla.suse.com/1276893

https://bugzilla.suse.com/1276894

https://bugzilla.suse.com/1276895

https://bugzilla.suse.com/1276896

https://bugzilla.suse.com/1276897

https://bugzilla.suse.com/1276898

https://bugzilla.suse.com/1276899

https://bugzilla.suse.com/1276900

https://bugzilla.suse.com/1276901

https://bugzilla.suse.com/1276902

https://www.suse.com/security/cve/CVE-2026-65182

https://www.suse.com/security/cve/CVE-2026-65183

https://www.suse.com/security/cve/CVE-2026-65637

https://www.suse.com/security/cve/CVE-2026-65905

https://www.suse.com/security/cve/CVE-2026-65927

https://www.suse.com/security/cve/CVE-2026-66299

https://www.suse.com/security/cve/CVE-2026-66422

https://www.suse.com/security/cve/CVE-2026-68525

https://www.suse.com/security/cve/CVE-2026-68569

https://www.suse.com/security/cve/CVE-2026-68763

https://www.suse.com/security/cve/CVE-2026-73180

http://www.nessus.org/u?46a6e1ff

Plugin Details

Severity: Medium

ID: 345835

File Name: suse_SU-2026-4119-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/15/2026

Updated: 9/15/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.23

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2026-66299

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:tomcat10-admin-webapps, p-cpe:/a:novell:suse_linux:tomcat10-el-5_0-api, p-cpe:/a:novell:suse_linux:tomcat10-jsp-3_1-api, p-cpe:/a:novell:suse_linux:tomcat10-lib, p-cpe:/a:novell:suse_linux:tomcat10-servlet-6_0-api, p-cpe:/a:novell:suse_linux:tomcat10-webapps, p-cpe:/a:novell:suse_linux:tomcat10

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 9/10/2026

Vulnerability Publication Date: 7/28/2026

Reference Information

CVE: CVE-2026-65182, CVE-2026-65183, CVE-2026-65637, CVE-2026-65905, CVE-2026-65927, CVE-2026-66299, CVE-2026-66422, CVE-2026-68525, CVE-2026-68569, CVE-2026-68763, CVE-2026-73180

IAVA: 2026-A-0902

SuSE: SUSE-SU-2026:4119-1