Upstream information
Description
Multiple cross-site scripting (XSS) vulnerabilities in the (1) Manager and (2) Host Manager web applications in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote authenticated users to inject arbitrary web script or HTML via a parameter name to manager/html/upload, and other unspecified vectors.NVD CVSS v2 Base Score: 3.5 (AV:N/AC:M/Au:S/C:N/I:P/A:N)
Novell/SUSE information
Novell Bugzilla entry: 292414, 427726 SUSE Security Advisories:- SUSE-SR:2009:004, published Tue, 17 Feb 2009 10:00:00 +0000
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| Novell Linux Desktop 9 SDK for x86 Novell Linux Desktop 9 SDK for x86_64 |
| core9.s390 sles9-oes.x86 YOU Patch Nr: 12116 |
| Open Enterprise Server |
| core9.s390 sles9-oes.x86 YOU Patch Nr: 12116 |
| SUSE LINUX 10.1 |
|
