Upstream information
Description
Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.NVD CVSS v2 Base Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N)
Novell/SUSE information
Novell Bugzilla entry: 655440 SUSE Security Advisories:- SUSE-SR:2011:003, published Tue, 08 Feb 2011 14:00:00 +0000
- openSUSE-SU-2011:0082-1, published Fri, 28 Jan 2011 19:08:14 +0100 (CET)
- openSUSE-SU-2011:0082-2, published Thu, 3 Feb 2011 15:08:12 +0100 (CET)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE Linux Enterprise Software Development Kit 11 SP1 |
| sle11-sp1-sdk.ppc sle11-sp1-sdk.x86 sle11-sp1-sdk.s390x sle11-sp1-sdk.ia64 sle11-sp1-sdk.x86-64 SAT Patch Nr: 3858 |
| openSUSE 11.2 |
| |
| openSUSE 11.3 |
| |
| openSUSE 11.2 |
|
