RHSA-2020:2529HighCVSS 7.0
Red Hat Security Advisory: tomcat6 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2020-9484 — tomcat: deserialization flaw in session persistence storage leading to RCE
🎯 Affected products46
- Red Hat Enterprise Linux Desktop Optional (v. 6)
- Red Hat Enterprise Linux HPC Node Optional (v. 6)
- Red Hat Enterprise Linux Server (v. 6)
- Red Hat Enterprise Linux Server Optional (v. 6)
- Red Hat Enterprise Linux Workstation (v. 6)
- Red Hat Enterprise Linux Workstation Optional (v. 6)
- tomcat6-0:6.0.24-115.el6_10.noarch as a component of Red Hat Enterprise Linux Desktop Optional (v. 6)
- tomcat6-0:6.0.24-115.el6_10.noarch as a component of Red Hat Enterprise Linux HPC Node Optional (v. 6)
- tomcat6-0:6.0.24-115.el6_10.noarch as a component of Red Hat Enterprise Linux Server (v. 6)
- tomcat6-0:6.0.24-115.el6_10.noarch as a component of Red Hat Enterprise Linux Workstation (v. 6)
- tomcat6-0:6.0.24-115.el6_10.src as a component of Red Hat Enterprise Linux Desktop Optional (v. 6)
- tomcat6-0:6.0.24-115.el6_10.src as a component of Red Hat Enterprise Linux HPC Node Optional (v. 6)
- tomcat6-0:6.0.24-115.el6_10.src as a component of Red Hat Enterprise Linux Server (v. 6)
- tomcat6-0:6.0.24-115.el6_10.src as a component of Red Hat Enterprise Linux Workstation (v. 6)
- tomcat6-admin-webapps-0:6.0.24-115.el6_10.noarch as a component of Red Hat Enterprise Linux Desktop Optional (v. 6)
- tomcat6-admin-webapps-0:6.0.24-115.el6_10.noarch as a component of Red Hat Enterprise Linux HPC Node Optional (v. 6)
- tomcat6-admin-webapps-0:6.0.24-115.el6_10.noarch as a component of Red Hat Enterprise Linux Server Optional (v. 6)
- tomcat6-admin-webapps-0:6.0.24-115.el6_10.noarch as a component of Red Hat Enterprise Linux Workstation Optional (v. 6)
- tomcat6-docs-webapp-0:6.0.24-115.el6_10.noarch as a component of Red Hat Enterprise Linux Desktop Optional (v. 6)
- tomcat6-docs-webapp-0:6.0.24-115.el6_10.noarch as a component of Red Hat Enterprise Linux HPC Node Optional (v. 6)
- tomcat6-docs-webapp-0:6.0.24-115.el6_10.noarch as a component of Red Hat Enterprise Linux Server Optional (v. 6)
- tomcat6-docs-webapp-0:6.0.24-115.el6_10.noarch as a component of Red Hat Enterprise Linux Workstation Optional (v. 6)
- tomcat6-el-2.1-api-0:6.0.24-115.el6_10.noarch as a component of Red Hat Enterprise Linux Desktop Optional (v. 6)
- tomcat6-el-2.1-api-0:6.0.24-115.el6_10.noarch as a component of Red Hat Enterprise Linux HPC Node Optional (v. 6)
- tomcat6-el-2.1-api-0:6.0.24-115.el6_10.noarch as a component of Red Hat Enterprise Linux Server (v. 6)
- tomcat6-el-2.1-api-0:6.0.24-115.el6_10.noarch as a component of Red Hat Enterprise Linux Workstation (v. 6)
- tomcat6-javadoc-0:6.0.24-115.el6_10.noarch as a component of Red Hat Enterprise Linux Desktop Optional (v. 6)
- tomcat6-javadoc-0:6.0.24-115.el6_10.noarch as a component of Red Hat Enterprise Linux HPC Node Optional (v. 6)
- tomcat6-javadoc-0:6.0.24-115.el6_10.noarch as a component of Red Hat Enterprise Linux Server Optional (v. 6)
- tomcat6-javadoc-0:6.0.24-115.el6_10.noarch as a component of Red Hat Enterprise Linux Workstation Optional (v. 6)
- +16 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Users may configure the PersistenceManager with an appropriate value for sessionAttributeValueClassNameFilter to ensure that only application provided attributes are serialized and deserialized. For more details about the configuration, refer to the Apache Tomcat 9 Configuration Reference https://tomcat.apache.org/tomcat-9.0-doc/config/manager.html.