RHSA-2020:2529: Important: tomcat6 security update
Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies.<br>Security Fix(es):<br><li> tomcat: deserialization flaw in session persistence storage leading to RCE (CVE-2020-9484)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:2529?
The severity of RHSA-2020:2529 is classified as critical due to a deserialization flaw that may lead to remote code execution.
How do I fix RHSA-2020:2529?
To fix RHSA-2020:2529, update Apache Tomcat to version 6.0.24-115.el6_10 or later.
What components are affected by RHSA-2020:2529?
RHSA-2020:2529 affects multiple components of Apache Tomcat, including tomcat6, tomcat6-admin-webapps, tomcat6-docs-webapp, and others.
What is CVE-2020-9484 related to RHSA-2020:2529?
CVE-2020-9484 describes a deserialization vulnerability in session persistence storage for Apache Tomcat leading to potential remote code execution.
Is there any workaround for RHSA-2020:2529?
There are no known workarounds for RHSA-2020:2529; the recommended action is to apply the security update.