RHSA-2021:0882LowCVSS 7.5

Red Hat Security Advisory: tomcat security update

Published
March 16, 2021
Last Modified
August 4, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2019-17563 — tomcat: Session fixation when using FORM authentication CVE-2020-1935 — tomcat: Mishandling of Transfer-Encoding header allows for HTTP request smuggling

🎯 Affected products51

  • Red Hat Enterprise Linux ComputeNode EUS (v. 7.6)
  • Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.6)
  • Red Hat Enterprise Linux Server EUS (v. 7.6)
  • Red Hat Enterprise Linux Server Optional EUS (v. 7.6)
  • Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7)
  • Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7)
  • tomcat-0:7.0.76-11.el7_6.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.6)
  • tomcat-0:7.0.76-11.el7_6.noarch as a component of Red Hat Enterprise Linux Server EUS (v. 7.6)
  • tomcat-0:7.0.76-11.el7_6.noarch as a component of Red Hat Enterprise Linux Server Optional EUS (v. 7.6)
  • tomcat-0:7.0.76-11.el7_6.noarch as a component of Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7)
  • tomcat-0:7.0.76-11.el7_6.noarch as a component of Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7)
  • tomcat-0:7.0.76-11.el7_6.src as a component of Red Hat Enterprise Linux ComputeNode EUS (v. 7.6)
  • tomcat-0:7.0.76-11.el7_6.src as a component of Red Hat Enterprise Linux Server EUS (v. 7.6)
  • tomcat-0:7.0.76-11.el7_6.src as a component of Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7)
  • tomcat-admin-webapps-0:7.0.76-11.el7_6.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.6)
  • tomcat-admin-webapps-0:7.0.76-11.el7_6.noarch as a component of Red Hat Enterprise Linux Server EUS (v. 7.6)
  • tomcat-admin-webapps-0:7.0.76-11.el7_6.noarch as a component of Red Hat Enterprise Linux Server Optional EUS (v. 7.6)
  • tomcat-admin-webapps-0:7.0.76-11.el7_6.noarch as a component of Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7)
  • tomcat-admin-webapps-0:7.0.76-11.el7_6.noarch as a component of Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7)
  • tomcat-docs-webapp-0:7.0.76-11.el7_6.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.6)
  • tomcat-docs-webapp-0:7.0.76-11.el7_6.noarch as a component of Red Hat Enterprise Linux Server Optional EUS (v. 7.6)
  • tomcat-docs-webapp-0:7.0.76-11.el7_6.noarch as a component of Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7)
  • tomcat-el-2.2-api-0:7.0.76-11.el7_6.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.6)
  • tomcat-el-2.2-api-0:7.0.76-11.el7_6.noarch as a component of Red Hat Enterprise Linux Server EUS (v. 7.6)
  • tomcat-el-2.2-api-0:7.0.76-11.el7_6.noarch as a component of Red Hat Enterprise Linux Server Optional EUS (v. 7.6)
  • tomcat-el-2.2-api-0:7.0.76-11.el7_6.noarch as a component of Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7)
  • tomcat-el-2.2-api-0:7.0.76-11.el7_6.noarch as a component of Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7)
  • tomcat-javadoc-0:7.0.76-11.el7_6.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.6)
  • tomcat-javadoc-0:7.0.76-11.el7_6.noarch as a component of Red Hat Enterprise Linux Server Optional EUS (v. 7.6)
  • tomcat-javadoc-0:7.0.76-11.el7_6.noarch as a component of Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7)
  • +21 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Workaround for Red Hat Satellite 6 is to add iptables rule to deny TCP requests of Tomcat that are not originating from the Satellite. For other Red Hat products, either mitigation isn't available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (5)