<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for tomcat11</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2025:02979-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2025-08-25T13:46:18Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2025-08-25T13:46:18Z</InitialReleaseDate>
    <CurrentReleaseDate>2025-08-25T13:46:18Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for tomcat11</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for tomcat11 fixes the following issues:

Updated to Tomcat 11.0.9
- CVE-2025-52520: Fixed integer overflow can lead to DoS for some unlikely configurations of multipart upload (bsc#1246388)
- CVE-2025-53506: Fixed uncontrolled resource HTTP/2 client consumption vulnerability (bsc#1246318)
    
Other:
- Correct a regression in the fix for CVE-2025-49125 that
  prevented access to PreResources and PostResources when mounted below the
  web application root with a path that was terminated with a file
  separator.
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">SUSE-2025-2979,SUSE-SLE-Module-Web-Scripting-15-SP6-2025-2979,SUSE-SLE-Module-Web-Scripting-15-SP7-2025-2979,openSUSE-SLE-15.6-2025-2979</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2025/suse-su-202502979-1/</URL>
      <Description>Link for SUSE-SU-2025:02979-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-updates/2025-August/041357.html</URL>
      <Description>E-Mail link for SUSE-SU-2025:02979-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1246318</URL>
      <Description>SUSE Bug 1246318</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1246388</URL>
      <Description>SUSE Bug 1246388</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2025-49125/</URL>
      <Description>SUSE CVE CVE-2025-49125 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2025-52520/</URL>
      <Description>SUSE CVE CVE-2025-52520 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2025-53506/</URL>
      <Description>SUSE CVE CVE-2025-53506 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Module for Web and Scripting 15 SP6">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 15 SP6">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP6" CPE="cpe:/o:suse:sle-module-web-scripting:15:sp6">SUSE Linux Enterprise Module for Web and Scripting 15 SP6</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Module for Web and Scripting 15 SP7">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 15 SP7">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP7" CPE="cpe:/o:suse:sle-module-web-scripting:15:sp7">SUSE Linux Enterprise Module for Web and Scripting 15 SP7</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="openSUSE Leap 15.6">
      <Branch Type="Product Name" Name="openSUSE Leap 15.6">
        <FullProductName ProductID="openSUSE Leap 15.6" CPE="cpe:/o:opensuse:leap:15.6">openSUSE Leap 15.6</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="tomcat11-11.0.9-150600.13.6.1">
      <FullProductName ProductID="tomcat11-11.0.9-150600.13.6.1">tomcat11-11.0.9-150600.13.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="tomcat11-admin-webapps-11.0.9-150600.13.6.1">
      <FullProductName ProductID="tomcat11-admin-webapps-11.0.9-150600.13.6.1">tomcat11-admin-webapps-11.0.9-150600.13.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="tomcat11-doc-11.0.9-150600.13.6.1">
      <FullProductName ProductID="tomcat11-doc-11.0.9-150600.13.6.1">tomcat11-doc-11.0.9-150600.13.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="tomcat11-docs-webapp-11.0.9-150600.13.6.1">
      <FullProductName ProductID="tomcat11-docs-webapp-11.0.9-150600.13.6.1">tomcat11-docs-webapp-11.0.9-150600.13.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="tomcat11-el-6_0-api-11.0.9-150600.13.6.1">
      <FullProductName ProductID="tomcat11-el-6_0-api-11.0.9-150600.13.6.1">tomcat11-el-6_0-api-11.0.9-150600.13.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="tomcat11-embed-11.0.9-150600.13.6.1">
      <FullProductName ProductID="tomcat11-embed-11.0.9-150600.13.6.1">tomcat11-embed-11.0.9-150600.13.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="tomcat11-jsp-4_0-api-11.0.9-150600.13.6.1">
      <FullProductName ProductID="tomcat11-jsp-4_0-api-11.0.9-150600.13.6.1">tomcat11-jsp-4_0-api-11.0.9-150600.13.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="tomcat11-jsvc-11.0.9-150600.13.6.1">
      <FullProductName ProductID="tomcat11-jsvc-11.0.9-150600.13.6.1">tomcat11-jsvc-11.0.9-150600.13.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="tomcat11-lib-11.0.9-150600.13.6.1">
      <FullProductName ProductID="tomcat11-lib-11.0.9-150600.13.6.1">tomcat11-lib-11.0.9-150600.13.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="tomcat11-servlet-6_1-api-11.0.9-150600.13.6.1">
      <FullProductName ProductID="tomcat11-servlet-6_1-api-11.0.9-150600.13.6.1">tomcat11-servlet-6_1-api-11.0.9-150600.13.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="tomcat11-webapps-11.0.9-150600.13.6.1">
      <FullProductName ProductID="tomcat11-webapps-11.0.9-150600.13.6.1">tomcat11-webapps-11.0.9-150600.13.6.1</FullProductName>
    </Branch>
    <Relationship ProductReference="tomcat11-11.0.9-150600.13.6.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP6:tomcat11-11.0.9-150600.13.6.1">tomcat11-11.0.9-150600.13.6.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat11-admin-webapps-11.0.9-150600.13.6.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP6:tomcat11-admin-webapps-11.0.9-150600.13.6.1">tomcat11-admin-webapps-11.0.9-150600.13.6.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat11-el-6_0-api-11.0.9-150600.13.6.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP6:tomcat11-el-6_0-api-11.0.9-150600.13.6.1">tomcat11-el-6_0-api-11.0.9-150600.13.6.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat11-jsp-4_0-api-11.0.9-150600.13.6.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP6:tomcat11-jsp-4_0-api-11.0.9-150600.13.6.1">tomcat11-jsp-4_0-api-11.0.9-150600.13.6.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat11-lib-11.0.9-150600.13.6.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP6:tomcat11-lib-11.0.9-150600.13.6.1">tomcat11-lib-11.0.9-150600.13.6.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat11-servlet-6_1-api-11.0.9-150600.13.6.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP6:tomcat11-servlet-6_1-api-11.0.9-150600.13.6.1">tomcat11-servlet-6_1-api-11.0.9-150600.13.6.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat11-webapps-11.0.9-150600.13.6.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP6:tomcat11-webapps-11.0.9-150600.13.6.1">tomcat11-webapps-11.0.9-150600.13.6.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat11-11.0.9-150600.13.6.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 15 SP7">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP7:tomcat11-11.0.9-150600.13.6.1">tomcat11-11.0.9-150600.13.6.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 15 SP7</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat11-admin-webapps-11.0.9-150600.13.6.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 15 SP7">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP7:tomcat11-admin-webapps-11.0.9-150600.13.6.1">tomcat11-admin-webapps-11.0.9-150600.13.6.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 15 SP7</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat11-el-6_0-api-11.0.9-150600.13.6.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 15 SP7">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP7:tomcat11-el-6_0-api-11.0.9-150600.13.6.1">tomcat11-el-6_0-api-11.0.9-150600.13.6.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 15 SP7</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat11-jsp-4_0-api-11.0.9-150600.13.6.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 15 SP7">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP7:tomcat11-jsp-4_0-api-11.0.9-150600.13.6.1">tomcat11-jsp-4_0-api-11.0.9-150600.13.6.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 15 SP7</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat11-lib-11.0.9-150600.13.6.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 15 SP7">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP7:tomcat11-lib-11.0.9-150600.13.6.1">tomcat11-lib-11.0.9-150600.13.6.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 15 SP7</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat11-servlet-6_1-api-11.0.9-150600.13.6.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 15 SP7">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP7:tomcat11-servlet-6_1-api-11.0.9-150600.13.6.1">tomcat11-servlet-6_1-api-11.0.9-150600.13.6.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 15 SP7</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat11-webapps-11.0.9-150600.13.6.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 15 SP7">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP7:tomcat11-webapps-11.0.9-150600.13.6.1">tomcat11-webapps-11.0.9-150600.13.6.1 as a component of SUSE Linux Enterprise Module for Web and Scripting 15 SP7</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat11-11.0.9-150600.13.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:tomcat11-11.0.9-150600.13.6.1">tomcat11-11.0.9-150600.13.6.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat11-admin-webapps-11.0.9-150600.13.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:tomcat11-admin-webapps-11.0.9-150600.13.6.1">tomcat11-admin-webapps-11.0.9-150600.13.6.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat11-doc-11.0.9-150600.13.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:tomcat11-doc-11.0.9-150600.13.6.1">tomcat11-doc-11.0.9-150600.13.6.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat11-docs-webapp-11.0.9-150600.13.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:tomcat11-docs-webapp-11.0.9-150600.13.6.1">tomcat11-docs-webapp-11.0.9-150600.13.6.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat11-el-6_0-api-11.0.9-150600.13.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:tomcat11-el-6_0-api-11.0.9-150600.13.6.1">tomcat11-el-6_0-api-11.0.9-150600.13.6.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat11-embed-11.0.9-150600.13.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:tomcat11-embed-11.0.9-150600.13.6.1">tomcat11-embed-11.0.9-150600.13.6.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat11-jsp-4_0-api-11.0.9-150600.13.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:tomcat11-jsp-4_0-api-11.0.9-150600.13.6.1">tomcat11-jsp-4_0-api-11.0.9-150600.13.6.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat11-jsvc-11.0.9-150600.13.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:tomcat11-jsvc-11.0.9-150600.13.6.1">tomcat11-jsvc-11.0.9-150600.13.6.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat11-lib-11.0.9-150600.13.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:tomcat11-lib-11.0.9-150600.13.6.1">tomcat11-lib-11.0.9-150600.13.6.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat11-servlet-6_1-api-11.0.9-150600.13.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:tomcat11-servlet-6_1-api-11.0.9-150600.13.6.1">tomcat11-servlet-6_1-api-11.0.9-150600.13.6.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat11-webapps-11.0.9-150600.13.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:tomcat11-webapps-11.0.9-150600.13.6.1">tomcat11-webapps-11.0.9-150600.13.6.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat.   When using PreResources or PostResources mounted other than at the root of the web application, it was possible to access those resources via an unexpected path. That path was likely not to be protected by the same security constraints as the expected path, allowing those security constraints to be bypassed.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105.
The following versions were EOL at the time the CVE was created but are 
known to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions 
may also be affected.


Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.</Note>
    </Notes>
    <CVE>CVE-2025-49125</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP6:tomcat11-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP6:tomcat11-admin-webapps-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP6:tomcat11-el-6_0-api-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP6:tomcat11-jsp-4_0-api-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP6:tomcat11-lib-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP6:tomcat11-servlet-6_1-api-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP6:tomcat11-webapps-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP7:tomcat11-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP7:tomcat11-admin-webapps-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP7:tomcat11-el-6_0-api-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP7:tomcat11-jsp-4_0-api-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP7:tomcat11-lib-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP7:tomcat11-servlet-6_1-api-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP7:tomcat11-webapps-11.0.9-150600.13.6.1</ProductID>
        <ProductID>openSUSE Leap 15.6:tomcat11-11.0.9-150600.13.6.1</ProductID>
        <ProductID>openSUSE Leap 15.6:tomcat11-admin-webapps-11.0.9-150600.13.6.1</ProductID>
        <ProductID>openSUSE Leap 15.6:tomcat11-doc-11.0.9-150600.13.6.1</ProductID>
        <ProductID>openSUSE Leap 15.6:tomcat11-docs-webapp-11.0.9-150600.13.6.1</ProductID>
        <ProductID>openSUSE Leap 15.6:tomcat11-el-6_0-api-11.0.9-150600.13.6.1</ProductID>
        <ProductID>openSUSE Leap 15.6:tomcat11-embed-11.0.9-150600.13.6.1</ProductID>
        <ProductID>openSUSE Leap 15.6:tomcat11-jsp-4_0-api-11.0.9-150600.13.6.1</ProductID>
        <ProductID>openSUSE Leap 15.6:tomcat11-jsvc-11.0.9-150600.13.6.1</ProductID>
        <ProductID>openSUSE Leap 15.6:tomcat11-lib-11.0.9-150600.13.6.1</ProductID>
        <ProductID>openSUSE Leap 15.6:tomcat11-servlet-6_1-api-11.0.9-150600.13.6.1</ProductID>
        <ProductID>openSUSE Leap 15.6:tomcat11-webapps-11.0.9-150600.13.6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2025/suse-su-202502979-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2025-49125.html</URL>
        <Description>CVE-2025-49125</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1244649</URL>
        <Description>SUSE Bug 1244649</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size limits.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106.
The following versions were EOL at the time the CVE was created but are 
known to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions 
may also be affected.


Users are recommended to upgrade to version 11.0.9, 10.1.43 or 9.0.107, which fix the issue.</Note>
    </Notes>
    <CVE>CVE-2025-52520</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP6:tomcat11-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP6:tomcat11-admin-webapps-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP6:tomcat11-el-6_0-api-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP6:tomcat11-jsp-4_0-api-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP6:tomcat11-lib-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP6:tomcat11-servlet-6_1-api-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP6:tomcat11-webapps-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP7:tomcat11-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP7:tomcat11-admin-webapps-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP7:tomcat11-el-6_0-api-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP7:tomcat11-jsp-4_0-api-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP7:tomcat11-lib-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP7:tomcat11-servlet-6_1-api-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP7:tomcat11-webapps-11.0.9-150600.13.6.1</ProductID>
        <ProductID>openSUSE Leap 15.6:tomcat11-11.0.9-150600.13.6.1</ProductID>
        <ProductID>openSUSE Leap 15.6:tomcat11-admin-webapps-11.0.9-150600.13.6.1</ProductID>
        <ProductID>openSUSE Leap 15.6:tomcat11-doc-11.0.9-150600.13.6.1</ProductID>
        <ProductID>openSUSE Leap 15.6:tomcat11-docs-webapp-11.0.9-150600.13.6.1</ProductID>
        <ProductID>openSUSE Leap 15.6:tomcat11-el-6_0-api-11.0.9-150600.13.6.1</ProductID>
        <ProductID>openSUSE Leap 15.6:tomcat11-embed-11.0.9-150600.13.6.1</ProductID>
        <ProductID>openSUSE Leap 15.6:tomcat11-jsp-4_0-api-11.0.9-150600.13.6.1</ProductID>
        <ProductID>openSUSE Leap 15.6:tomcat11-jsvc-11.0.9-150600.13.6.1</ProductID>
        <ProductID>openSUSE Leap 15.6:tomcat11-lib-11.0.9-150600.13.6.1</ProductID>
        <ProductID>openSUSE Leap 15.6:tomcat11-servlet-6_1-api-11.0.9-150600.13.6.1</ProductID>
        <ProductID>openSUSE Leap 15.6:tomcat11-webapps-11.0.9-150600.13.6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2025/suse-su-202502979-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2025-52520.html</URL>
        <Description>CVE-2025-52520</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1246388</URL>
        <Description>SUSE Bug 1246388</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent streams.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106.
The following versions were EOL at the time the CVE was created but are 
known to be affected: 8.5.0 through 8.5.100.


Users are recommended to upgrade to version 11.0.9, 10.1.43 or 9.0.107, which fix the issue.</Note>
    </Notes>
    <CVE>CVE-2025-53506</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP6:tomcat11-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP6:tomcat11-admin-webapps-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP6:tomcat11-el-6_0-api-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP6:tomcat11-jsp-4_0-api-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP6:tomcat11-lib-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP6:tomcat11-servlet-6_1-api-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP6:tomcat11-webapps-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP7:tomcat11-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP7:tomcat11-admin-webapps-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP7:tomcat11-el-6_0-api-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP7:tomcat11-jsp-4_0-api-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP7:tomcat11-lib-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP7:tomcat11-servlet-6_1-api-11.0.9-150600.13.6.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP7:tomcat11-webapps-11.0.9-150600.13.6.1</ProductID>
        <ProductID>openSUSE Leap 15.6:tomcat11-11.0.9-150600.13.6.1</ProductID>
        <ProductID>openSUSE Leap 15.6:tomcat11-admin-webapps-11.0.9-150600.13.6.1</ProductID>
        <ProductID>openSUSE Leap 15.6:tomcat11-doc-11.0.9-150600.13.6.1</ProductID>
        <ProductID>openSUSE Leap 15.6:tomcat11-docs-webapp-11.0.9-150600.13.6.1</ProductID>
        <ProductID>openSUSE Leap 15.6:tomcat11-el-6_0-api-11.0.9-150600.13.6.1</ProductID>
        <ProductID>openSUSE Leap 15.6:tomcat11-embed-11.0.9-150600.13.6.1</ProductID>
        <ProductID>openSUSE Leap 15.6:tomcat11-jsp-4_0-api-11.0.9-150600.13.6.1</ProductID>
        <ProductID>openSUSE Leap 15.6:tomcat11-jsvc-11.0.9-150600.13.6.1</ProductID>
        <ProductID>openSUSE Leap 15.6:tomcat11-lib-11.0.9-150600.13.6.1</ProductID>
        <ProductID>openSUSE Leap 15.6:tomcat11-servlet-6_1-api-11.0.9-150600.13.6.1</ProductID>
        <ProductID>openSUSE Leap 15.6:tomcat11-webapps-11.0.9-150600.13.6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2025/suse-su-202502979-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2025-53506.html</URL>
        <Description>CVE-2025-53506</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1246318</URL>
        <Description>SUSE Bug 1246318</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
