SUSE Linux Enterprise Server和SUSE Enterprise Storage都是德国SUSE公司的产品。SUSE Linux Enterprise Server是一套企业服务器版Linux操作系统。SUSE Enterprise Storage是一套软件定义的储存解决方案。 多款SUSE产品中的tomcat存在安全漏洞。本地攻击者可利用该漏洞提升权限。以下产品及版本受到影响:SUSE Enterprise Storage 5版本(tomcat 8.0.53-29.32.1之前版
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SUSE | SUSE Enterprise Storage 5 | tomcat ~ 8.0.53-29.32.1 | - |
|
| SUSE | SUSE Linux Enterprise Server 12-SP2-BCL | tomcat ~ 8.0.53-29.32.1 | - |
|
| SUSE | SUSE Linux Enterprise Server 12-SP2-LTSS | tomcat ~ 8.0.53-29.32.1 | - |
|
| SUSE | SUSE Linux Enterprise Server 12-SP3-BCL | tomcat ~ 8.0.53-29.32.1 | - |
|
| SUSE | SUSE Linux Enterprise Server 12-SP3-LTSS | tomcat ~ 8.0.53-29.32.1 | - |
|
| SUSE | SUSE Linux Enterprise Server 12-SP4 | tomcat ~ 9.0.35-3.39.1 | - |
|
| SUSE | SUSE Linux Enterprise Server 12-SP5 | tomcat ~ 9.0.35-3.39.1 | - |
|
| SUSE | SUSE Linux Enterprise Server 15-LTSS | tomcat ~ 9.0.35-3.57.3 | - |
|
| SUSE | SUSE Linux Enterprise Server for SAP 12-SP2 | tomcat ~ 8.0.53-29.32.1 | - |
|
| SUSE | SUSE Linux Enterprise Server for SAP 12-SP3 | tomcat ~ 8.0.53-29.32.1 | - |
|
| SUSE | SUSE Linux Enterprise Server for SAP 15 | tomcat ~ 9.0.35-3.57.3 | - |
|
| SUSE | SUSE OpenStack Cloud 7 | tomcat ~ 8.0.53-29.32.1 | - |
|
| SUSE | SUSE OpenStack Cloud 8 | tomcat ~ 8.0.53-29.32.1 | - |
|
| SUSE | SUSE OpenStack Cloud Crowbar 8 | tomcat ~ 8.0.53-29.32.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-8019 | 7.7 HIGH | syslog-ng: Local privilege escalation from new to root in %post |
| CVE-2019-3681 | 7.5 HIGH | osc: stores downloaded (supposed) RPM in network-controlled filesystem paths |
No comments yet