Apache Tomcat security updates

Number: AV18-140
Date: 21 August 2018

Purpose

The purpose of this Advisory is to bring attention to Apache Tomcat security updates.

Assessment

Vulnerabilities in Apache Tomcat's Native Connector could allow an unauthenticated, remote user to obtain sensitive information or cause a denial of service condition.

Affected Versions:

  • Fixed in Apache Tomcat Native Connector 1.2.17
  • Fixed in Apache Tomcat Native Connector 1.2.16

CVE References: CVE-2018-8019, CVE-2017-15698

Suggested action

CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.

References

http://tomcat.apache.org/security-native.html 
https://tomcat.apache.org/download-native.cgi

Date modified: