SuSE 10 Security Update : Websphere Community Edition (ZYPP Patch Number 5850)

High Nessus Plugin ID 41596


The remote SuSE 10 host is missing a security-related patch.


Websphere has been updated to version to fix several security vulnerabilities in the included subprojects, such as Apache Geronimo and Tomcat. (CVE-2007-0184 / CVE-2007-0185 / CVE-2007-2377 / CVE-2007-2449 / CVE-2007-2450 / CVE-2007-3382 / CVE-2007-3385 / CVE-2007-3386 / CVE-2007-5333 / CVE-2007-5342 / CVE-2007-5461 / CVE-2007-5613 / CVE-2007-5615 / CVE-2007-6286 / CVE-2008-0002 / CVE-2008-1232 / CVE-2008-1947 / CVE-2008-2370 / CVE-2008-2938)


Apply ZYPP patch number 5850.

See Also

Plugin Details

Severity: High

ID: 41596

File Name: suse_websphere-as_ce-5850.nasl

Version: $Revision: 1.13 $

Type: local

Agent: unix

Published: 2009/09/24

Modified: 2016/12/22

Dependencies: 12634

Risk Information

Risk Factor: High


Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: cpe:/o:suse:suse_linux

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2008/12/03

Exploitable With

CANVAS (D2ExploitPack)

Elliot (Apache Tomcat File Disclosure)

Reference Information

CVE: CVE-2007-0184, CVE-2007-0185, CVE-2007-2377, CVE-2007-2449, CVE-2007-2450, CVE-2007-3382, CVE-2007-3385, CVE-2007-3386, CVE-2007-5333, CVE-2007-5342, CVE-2007-5461, CVE-2007-5613, CVE-2007-5615, CVE-2007-6286, CVE-2008-0002, CVE-2008-1232, CVE-2008-1947, CVE-2008-2370, CVE-2008-2938

CWE: 22, 79, 94, 200, 264