RHSA-2020:0855HighCVSS 7.6
Red Hat Security Advisory: tomcat security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2020-1938 — tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability
🎯 Affected products58
- Red Hat Enterprise Linux Client (v. 7)
- Red Hat Enterprise Linux Client Optional (v. 7)
- Red Hat Enterprise Linux ComputeNode (v. 7)
- Red Hat Enterprise Linux ComputeNode Optional (v. 7)
- Red Hat Enterprise Linux Server (v. 7)
- Red Hat Enterprise Linux Server Optional (v. 7)
- Red Hat Enterprise Linux Workstation (v. 7)
- Red Hat Enterprise Linux Workstation Optional (v. 7)
- tomcat-0:7.0.76-11.el7_7.noarch as a component of Red Hat Enterprise Linux Client Optional (v. 7)
- tomcat-0:7.0.76-11.el7_7.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional (v. 7)
- tomcat-0:7.0.76-11.el7_7.noarch as a component of Red Hat Enterprise Linux Server (v. 7)
- tomcat-0:7.0.76-11.el7_7.noarch as a component of Red Hat Enterprise Linux Server Optional (v. 7)
- tomcat-0:7.0.76-11.el7_7.noarch as a component of Red Hat Enterprise Linux Workstation (v. 7)
- tomcat-0:7.0.76-11.el7_7.src as a component of Red Hat Enterprise Linux Client (v. 7)
- tomcat-0:7.0.76-11.el7_7.src as a component of Red Hat Enterprise Linux ComputeNode (v. 7)
- tomcat-0:7.0.76-11.el7_7.src as a component of Red Hat Enterprise Linux Server (v. 7)
- tomcat-0:7.0.76-11.el7_7.src as a component of Red Hat Enterprise Linux Workstation (v. 7)
- tomcat-admin-webapps-0:7.0.76-11.el7_7.noarch as a component of Red Hat Enterprise Linux Client Optional (v. 7)
- tomcat-admin-webapps-0:7.0.76-11.el7_7.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional (v. 7)
- tomcat-admin-webapps-0:7.0.76-11.el7_7.noarch as a component of Red Hat Enterprise Linux Server (v. 7)
- tomcat-admin-webapps-0:7.0.76-11.el7_7.noarch as a component of Red Hat Enterprise Linux Server Optional (v. 7)
- tomcat-admin-webapps-0:7.0.76-11.el7_7.noarch as a component of Red Hat Enterprise Linux Workstation (v. 7)
- tomcat-docs-webapp-0:7.0.76-11.el7_7.noarch as a component of Red Hat Enterprise Linux Client Optional (v. 7)
- tomcat-docs-webapp-0:7.0.76-11.el7_7.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional (v. 7)
- tomcat-docs-webapp-0:7.0.76-11.el7_7.noarch as a component of Red Hat Enterprise Linux Server Optional (v. 7)
- tomcat-docs-webapp-0:7.0.76-11.el7_7.noarch as a component of Red Hat Enterprise Linux Workstation Optional (v. 7)
- tomcat-el-2.2-api-0:7.0.76-11.el7_7.noarch as a component of Red Hat Enterprise Linux Client Optional (v. 7)
- tomcat-el-2.2-api-0:7.0.76-11.el7_7.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional (v. 7)
- tomcat-el-2.2-api-0:7.0.76-11.el7_7.noarch as a component of Red Hat Enterprise Linux Server (v. 7)
- tomcat-el-2.2-api-0:7.0.76-11.el7_7.noarch as a component of Red Hat Enterprise Linux Server Optional (v. 7)
- +28 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Please refer to the Red Hat knowledgebase article: https://access.redhat.com/solutions/4851251