openSUSE-SU-2026:11399-1: moderate: tomcat-9.0.120-1.1 on GA media

[email protected] Fri, 31 Jul 2026 17:37:06 +0200 (CEST)
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
# tomcat-9.0.120-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11399-1
Rating: moderate

Cross-References:

  * CVE-2026-59083
  * CVE-2026-59084



CVSS scores:

  * CVE-2026-59083 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
  * CVE-2026-59084 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Affected Products:

  * openSUSE Tumbleweed


An update that solves 2 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the tomcat-9.0.120-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

  * openSUSE Tumbleweed:
    * tomcat 9.0.120-1.1
    * tomcat-admin-webapps 9.0.120-1.1
    * tomcat-docs-webapp 9.0.120-1.1
    * tomcat-el-3_0-api 9.0.120-1.1
    * tomcat-embed 9.0.120-1.1
    * tomcat-javadoc 9.0.120-1.1
    * tomcat-jsp-2_3-api 9.0.120-1.1
    * tomcat-jsvc 9.0.120-1.1
    * tomcat-lib 9.0.120-1.1
    * tomcat-servlet-4_0-api 9.0.120-1.1
    * tomcat-webapps 9.0.120-1.1

## References:

  * https://www.suse.com/security/cve/CVE-2026-59083.html
  * https://www.suse.com/security/cve/CVE-2026-59084.html