<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for tomcat6</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2015:1337-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2013-08-02T13:29:14Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2013-08-02T13:29:14Z</InitialReleaseDate>
    <CurrentReleaseDate>2013-08-02T13:29:14Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for tomcat6</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">
This update of tomcat6 fixes:

    * apache-tomcat-CVE-2012-3544.patch (bnc#831119)
    * use chown --no-dereference to prevent symlink attacks on log
      (bnc#822177#c7/prevents CVE-2013-1976)
    * Fix tomcat init scripts generating malformed classpath (
      http://youtrack.jetbrains.com/issue/JT-18545
      &lt;http://youtrack.jetbrains.com/issue/JT-18545&gt; ) bnc#804992 (patch
      from m407)
    * fix a typo in initscript (bnc#768772 )
    * copy all shell scripts (bnc#818948)

Security Issue references:

    * CVE-2012-3544
      &lt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3544&gt;
    * CVE-2013-1976
      &lt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1976&gt;
    * CVE-2012-0022
      &lt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0022&gt;

</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">slessp3-tomcat6</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20151337-1/</URL>
      <Description>Link for SUSE-SU-2015:1337-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2015-August/001523.html</URL>
      <Description>E-Mail link for SUSE-SU-2015:1337-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/768772</URL>
      <Description>SUSE Bug 768772</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/804992</URL>
      <Description>SUSE Bug 804992</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/818948</URL>
      <Description>SUSE Bug 818948</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/822177</URL>
      <Description>SUSE Bug 822177</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/831119</URL>
      <Description>SUSE Bug 831119</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/906152</URL>
      <Description>SUSE Bug 906152</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/917127</URL>
      <Description>SUSE Bug 917127</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/918195</URL>
      <Description>SUSE Bug 918195</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/926762</URL>
      <Description>SUSE Bug 926762</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/931442</URL>
      <Description>SUSE Bug 931442</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/932698</URL>
      <Description>SUSE Bug 932698</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2012-0022/</URL>
      <Description>SUSE CVE CVE-2012-0022 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2012-3544/</URL>
      <Description>SUSE CVE CVE-2012-3544 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2013-1976/</URL>
      <Description>SUSE CVE CVE-2013-1976 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-0227/</URL>
      <Description>SUSE CVE CVE-2014-0227 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-0230/</URL>
      <Description>SUSE CVE CVE-2014-0230 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-7810/</URL>
      <Description>SUSE CVE CVE-2014-7810 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 11 SP3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 11 SP3">
        <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3" CPE="cpe:/o:suse:suse_sles:11:sp3">SUSE Linux Enterprise Server 11 SP3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 11 SP3-TERADATA">
        <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA" CPE="cpe:/o:suse:sles:11:sp3:teradata">SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 11 SP3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server for SAP Applications 11 SP3">
        <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 11 SP3" CPE="cpe:/o:suse:sles_sap:11:sp3">SUSE Linux Enterprise Server for SAP Applications 11 SP3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="tomcat6-6.0.18-20.35.42.1">
      <FullProductName ProductID="tomcat6-6.0.18-20.35.42.1">tomcat6-6.0.18-20.35.42.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="tomcat6-admin-webapps-6.0.18-20.35.42.1">
      <FullProductName ProductID="tomcat6-admin-webapps-6.0.18-20.35.42.1">tomcat6-admin-webapps-6.0.18-20.35.42.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="tomcat6-docs-webapp-6.0.18-20.35.42.1">
      <FullProductName ProductID="tomcat6-docs-webapp-6.0.18-20.35.42.1">tomcat6-docs-webapp-6.0.18-20.35.42.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="tomcat6-javadoc-6.0.18-20.35.42.1">
      <FullProductName ProductID="tomcat6-javadoc-6.0.18-20.35.42.1">tomcat6-javadoc-6.0.18-20.35.42.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="tomcat6-jsp-2_1-api-6.0.18-20.35.42.1">
      <FullProductName ProductID="tomcat6-jsp-2_1-api-6.0.18-20.35.42.1">tomcat6-jsp-2_1-api-6.0.18-20.35.42.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="tomcat6-lib-6.0.18-20.35.42.1">
      <FullProductName ProductID="tomcat6-lib-6.0.18-20.35.42.1">tomcat6-lib-6.0.18-20.35.42.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="tomcat6-servlet-2_5-api-6.0.18-20.35.42.1">
      <FullProductName ProductID="tomcat6-servlet-2_5-api-6.0.18-20.35.42.1">tomcat6-servlet-2_5-api-6.0.18-20.35.42.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="tomcat6-webapps-6.0.18-20.35.42.1">
      <FullProductName ProductID="tomcat6-webapps-6.0.18-20.35.42.1">tomcat6-webapps-6.0.18-20.35.42.1</FullProductName>
    </Branch>
    <Relationship ProductReference="tomcat6-6.0.18-20.35.42.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3:tomcat6-6.0.18-20.35.42.1">tomcat6-6.0.18-20.35.42.1 as a component of SUSE Linux Enterprise Server 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat6-admin-webapps-6.0.18-20.35.42.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3:tomcat6-admin-webapps-6.0.18-20.35.42.1">tomcat6-admin-webapps-6.0.18-20.35.42.1 as a component of SUSE Linux Enterprise Server 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat6-docs-webapp-6.0.18-20.35.42.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3:tomcat6-docs-webapp-6.0.18-20.35.42.1">tomcat6-docs-webapp-6.0.18-20.35.42.1 as a component of SUSE Linux Enterprise Server 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat6-javadoc-6.0.18-20.35.42.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3:tomcat6-javadoc-6.0.18-20.35.42.1">tomcat6-javadoc-6.0.18-20.35.42.1 as a component of SUSE Linux Enterprise Server 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat6-jsp-2_1-api-6.0.18-20.35.42.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3:tomcat6-jsp-2_1-api-6.0.18-20.35.42.1">tomcat6-jsp-2_1-api-6.0.18-20.35.42.1 as a component of SUSE Linux Enterprise Server 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat6-lib-6.0.18-20.35.42.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3:tomcat6-lib-6.0.18-20.35.42.1">tomcat6-lib-6.0.18-20.35.42.1 as a component of SUSE Linux Enterprise Server 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat6-servlet-2_5-api-6.0.18-20.35.42.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3:tomcat6-servlet-2_5-api-6.0.18-20.35.42.1">tomcat6-servlet-2_5-api-6.0.18-20.35.42.1 as a component of SUSE Linux Enterprise Server 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat6-webapps-6.0.18-20.35.42.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3:tomcat6-webapps-6.0.18-20.35.42.1">tomcat6-webapps-6.0.18-20.35.42.1 as a component of SUSE Linux Enterprise Server 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat6-6.0.18-20.35.42.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-6.0.18-20.35.42.1">tomcat6-6.0.18-20.35.42.1 as a component of SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat6-admin-webapps-6.0.18-20.35.42.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-admin-webapps-6.0.18-20.35.42.1">tomcat6-admin-webapps-6.0.18-20.35.42.1 as a component of SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat6-docs-webapp-6.0.18-20.35.42.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-docs-webapp-6.0.18-20.35.42.1">tomcat6-docs-webapp-6.0.18-20.35.42.1 as a component of SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat6-javadoc-6.0.18-20.35.42.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-javadoc-6.0.18-20.35.42.1">tomcat6-javadoc-6.0.18-20.35.42.1 as a component of SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat6-jsp-2_1-api-6.0.18-20.35.42.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-jsp-2_1-api-6.0.18-20.35.42.1">tomcat6-jsp-2_1-api-6.0.18-20.35.42.1 as a component of SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat6-lib-6.0.18-20.35.42.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-lib-6.0.18-20.35.42.1">tomcat6-lib-6.0.18-20.35.42.1 as a component of SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat6-servlet-2_5-api-6.0.18-20.35.42.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-servlet-2_5-api-6.0.18-20.35.42.1">tomcat6-servlet-2_5-api-6.0.18-20.35.42.1 as a component of SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat6-webapps-6.0.18-20.35.42.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-webapps-6.0.18-20.35.42.1">tomcat6-webapps-6.0.18-20.35.42.1 as a component of SUSE Linux Enterprise Server 11 SP3-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat6-6.0.18-20.35.42.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-6.0.18-20.35.42.1">tomcat6-6.0.18-20.35.42.1 as a component of SUSE Linux Enterprise Server for SAP Applications 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat6-admin-webapps-6.0.18-20.35.42.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-admin-webapps-6.0.18-20.35.42.1">tomcat6-admin-webapps-6.0.18-20.35.42.1 as a component of SUSE Linux Enterprise Server for SAP Applications 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat6-docs-webapp-6.0.18-20.35.42.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-docs-webapp-6.0.18-20.35.42.1">tomcat6-docs-webapp-6.0.18-20.35.42.1 as a component of SUSE Linux Enterprise Server for SAP Applications 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat6-javadoc-6.0.18-20.35.42.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-javadoc-6.0.18-20.35.42.1">tomcat6-javadoc-6.0.18-20.35.42.1 as a component of SUSE Linux Enterprise Server for SAP Applications 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat6-jsp-2_1-api-6.0.18-20.35.42.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-jsp-2_1-api-6.0.18-20.35.42.1">tomcat6-jsp-2_1-api-6.0.18-20.35.42.1 as a component of SUSE Linux Enterprise Server for SAP Applications 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat6-lib-6.0.18-20.35.42.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-lib-6.0.18-20.35.42.1">tomcat6-lib-6.0.18-20.35.42.1 as a component of SUSE Linux Enterprise Server for SAP Applications 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat6-servlet-2_5-api-6.0.18-20.35.42.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-servlet-2_5-api-6.0.18-20.35.42.1">tomcat6-servlet-2_5-api-6.0.18-20.35.42.1 as a component of SUSE Linux Enterprise Server for SAP Applications 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat6-webapps-6.0.18-20.35.42.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-webapps-6.0.18-20.35.42.1">tomcat6-webapps-6.0.18-20.35.42.1 as a component of SUSE Linux Enterprise Server for SAP Applications 11 SP3</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote attackers to cause a denial of service (CPU consumption) via a request that contains many parameters and parameter values, a different vulnerability than CVE-2011-4858.</Note>
    </Notes>
    <CVE>CVE-2012-0022</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-admin-webapps-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-docs-webapp-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-javadoc-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-jsp-2_1-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-lib-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-servlet-2_5-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-webapps-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-admin-webapps-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-docs-webapp-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-javadoc-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-jsp-2_1-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-lib-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-servlet-2_5-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-webapps-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-admin-webapps-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-docs-webapp-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-javadoc-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-jsp-2_1-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-lib-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-servlet-2_5-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-webapps-6.0.18-20.35.42.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20151337-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2012-0022.html</URL>
        <Description>CVE-2012-0022</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/742477</URL>
        <Description>SUSE Bug 742477</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/745056</URL>
        <Description>SUSE Bug 745056</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attackers to cause a denial of service by streaming data.</Note>
    </Notes>
    <CVE>CVE-2012-3544</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-admin-webapps-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-docs-webapp-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-javadoc-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-jsp-2_1-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-lib-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-servlet-2_5-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-webapps-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-admin-webapps-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-docs-webapp-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-javadoc-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-jsp-2_1-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-lib-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-servlet-2_5-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-webapps-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-admin-webapps-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-docs-webapp-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-javadoc-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-jsp-2_1-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-lib-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-servlet-2_5-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-webapps-6.0.18-20.35.42.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>2.1</BaseScore>
        <Vector>AV:N/AC:H/Au:S/C:P/I:N/A:N</Vector>
      </ScoreSet>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20151337-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2012-3544.html</URL>
        <Description>CVE-2012-3544</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/822177</URL>
        <Description>SUSE Bug 822177</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/831119</URL>
        <Description>SUSE Bug 831119</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/865746</URL>
        <Description>SUSE Bug 865746</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The (1) tomcat5, (2) tomcat6, and (3) tomcat7 init scripts, as used in the RPM distribution of Tomcat for JBoss Enterprise Web Server 1.0.2 and 2.0.0, and Red Hat Enterprise Linux 5 and 6, allow local users to change the ownership of arbitrary files via a symlink attack on (a) tomcat5-initd.log, (b) tomcat6-initd.log, (c) catalina.out, or (d) tomcat7-initd.log.</Note>
    </Notes>
    <CVE>CVE-2013-1976</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-admin-webapps-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-docs-webapp-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-javadoc-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-jsp-2_1-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-lib-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-servlet-2_5-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-webapps-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-admin-webapps-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-docs-webapp-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-javadoc-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-jsp-2_1-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-lib-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-servlet-2_5-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-webapps-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-admin-webapps-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-docs-webapp-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-javadoc-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-jsp-2_1-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-lib-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-servlet-2_5-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-webapps-6.0.18-20.35.42.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.9</BaseScore>
        <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20151337-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2013-1976.html</URL>
        <Description>CVE-2013-1976</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/822177</URL>
        <Description>SUSE Bug 822177</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat 6.x before 6.0.42, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle attempts to continue reading data after an error has occurred, which allows remote attackers to conduct HTTP request smuggling attacks or cause a denial of service (resource consumption) by streaming data with malformed chunked transfer coding.</Note>
    </Notes>
    <CVE>CVE-2014-0227</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-admin-webapps-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-docs-webapp-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-javadoc-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-jsp-2_1-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-lib-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-servlet-2_5-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-webapps-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-admin-webapps-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-docs-webapp-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-javadoc-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-jsp-2_1-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-lib-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-servlet-2_5-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-webapps-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-admin-webapps-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-docs-webapp-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-javadoc-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-jsp-2_1-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-lib-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-servlet-2_5-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-webapps-6.0.18-20.35.42.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.4</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20151337-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-0227.html</URL>
        <Description>CVE-2014-0227</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/917127</URL>
        <Description>SUSE Bug 917127</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/926762</URL>
        <Description>SUSE Bug 926762</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/988489</URL>
        <Description>SUSE Bug 988489</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP response occurs before finishing the reading of an entire request body, which allows remote attackers to cause a denial of service (thread consumption) via a series of aborted upload attempts.</Note>
    </Notes>
    <CVE>CVE-2014-0230</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-admin-webapps-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-docs-webapp-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-javadoc-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-jsp-2_1-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-lib-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-servlet-2_5-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-webapps-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-admin-webapps-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-docs-webapp-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-javadoc-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-jsp-2_1-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-lib-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-servlet-2_5-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-webapps-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-admin-webapps-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-docs-webapp-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-javadoc-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-jsp-2_1-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-lib-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-servlet-2_5-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-webapps-6.0.18-20.35.42.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.8</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20151337-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-0230.html</URL>
        <Description>CVE-2014-0230</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/926762</URL>
        <Description>SUSE Bug 926762</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/988489</URL>
        <Description>SUSE Bug 988489</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypass a SecurityManager protection mechanism via a web application that leverages use of incorrect privileges during EL evaluation.</Note>
    </Notes>
    <CVE>CVE-2014-7810</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-admin-webapps-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-docs-webapp-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-javadoc-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-jsp-2_1-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-lib-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-servlet-2_5-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3-TERADATA:tomcat6-webapps-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-admin-webapps-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-docs-webapp-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-javadoc-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-jsp-2_1-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-lib-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-servlet-2_5-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:tomcat6-webapps-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-admin-webapps-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-docs-webapp-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-javadoc-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-jsp-2_1-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-lib-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-servlet-2_5-api-6.0.18-20.35.42.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 11 SP3:tomcat6-webapps-6.0.18-20.35.42.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20151337-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-7810.html</URL>
        <Description>CVE-2014-7810</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/931442</URL>
        <Description>SUSE Bug 931442</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
