USN-7242-1: Tomcat vulnerability
Published Jan 30, 2025
·Updated
Pierre Ernst discovered that the Tomcat JmxRemoteLifecycleListener did not implement a recommended fix. A remote attacker could possibly use this issue to execute arbitrary code.
Affected Software
2 affected componentsFixes available
All of the following
ubuntu/libservlet2.5-java<6.0.39-1ubuntu0.1+esm2
6.0.39-1ubuntu0.1+esm2
Ubuntu Ubuntu=14.04
Event History
Jan 30, 2025
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7242-1?
USN-7242-1 is considered critical due to the potential for remote code execution.
2
How do I fix USN-7242-1?
To fix USN-7242-1, update the libservlet2.5-java package to version 6.0.39-1ubuntu0.1+esm2.
3
What software is affected by USN-7242-1?
USN-7242-1 affects Ubuntu 14.04 with the libservlet2.5-java package.
4
Who discovered the vulnerability in USN-7242-1?
The vulnerability addressed in USN-7242-1 was discovered by Pierre Ernst.
5
Can USN-7242-1 lead to unauthorized access?
Yes, USN-7242-1 can potentially allow a remote attacker to execute arbitrary code, leading to unauthorized access.