CVE-2020-8022
Published: Jun 29, 2020
Modified: Sep 17, 2024
CVSS v3.1
7.7
Description
A Incorrect Default Permissions vulnerability in the packaging of tomcat on SUSE Enterprise Storage 5, SUSE Linux Enterprise Server 12-SP2-BCL, SUSE Linux Enterprise Server 12-SP2-LTSS, SUSE Linux Enterprise Server 12-SP3-BCL, SUSE Linux Enterprise Server 12-SP3-LTSS, SUSE Linux Enterprise Server 12-SP4, SUSE Linux Enterprise Server 12-SP5, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 12-SP2, SUSE Linux Enterprise Server for SAP 12-SP3, SUSE Linux Enterprise Server for SAP 15, SUSE OpenStack Cloud 7, SUSE OpenStack Cloud 8, SUSE OpenStack Cloud Crowbar 8 allows local attackers to escalate from group tomcat to root. This issue affects: SUSE Enterprise Storage 5 tomcat versions prior to 8.0.53-29.32.1. SUSE Linux Enterprise Server 12-SP2-BCL tomcat versions prior to 8.0.53-29.32.1. SUSE Linux Enterprise Server 12-SP2-LTSS tomcat versions prior to 8.0.53-29.32.1. SUSE Linux Enterprise Server 12-SP3-BCL tomcat versions prior to 8.0.53-29.32.1. SUSE Linux Enterprise Server 12-SP3-LTSS tomcat versions prior to 8.0.53-29.32.1. SUSE Linux Enterprise Server 12-SP4 tomcat versions prior to 9.0.35-3.39.1. SUSE Linux Enterprise Server 12-SP5 tomcat versions prior to 9.0.35-3.39.1. SUSE Linux Enterprise Server 15-LTSS tomcat versions prior to 9.0.35-3.57.3. SUSE Linux Enterprise Server for SAP 12-SP2 tomcat versions prior to 8.0.53-29.32.1. SUSE Linux Enterprise Server for SAP 12-SP3 tomcat versions prior to 8.0.53-29.32.1. SUSE Linux Enterprise Server for SAP 15 tomcat versions prior to 9.0.35-3.57.3. SUSE OpenStack Cloud 7 tomcat versions prior to 8.0.53-29.32.1. SUSE OpenStack Cloud 8 tomcat versions prior to 8.0.53-29.32.1. SUSE OpenStack Cloud Crowbar 8 tomcat versions prior to 8.0.53-29.32.1.
| Vendor | Product | Versions |
|---|---|---|
SUSE | SUSE Enterprise Storage 5 | affected tomcat - < 8.0.53-29.32.1 |
SUSE | SUSE Linux Enterprise Server 12-SP2-BCL | affected tomcat - < 8.0.53-29.32.1 |
SUSE | SUSE Linux Enterprise Server 12-SP2-LTSS | affected tomcat - < 8.0.53-29.32.1 |
SUSE | SUSE Linux Enterprise Server 12-SP3-BCL | affected tomcat - < 8.0.53-29.32.1 |
SUSE | SUSE Linux Enterprise Server 12-SP3-LTSS | affected tomcat - < 8.0.53-29.32.1 |
SUSE | SUSE Linux Enterprise Server 12-SP4 | affected tomcat - < 9.0.35-3.39.1 |
SUSE | SUSE Linux Enterprise Server 12-SP5 | affected tomcat - < 9.0.35-3.39.1 |
SUSE | SUSE Linux Enterprise Server 15-LTSS | affected tomcat - < 9.0.35-3.57.3 |
SUSE | SUSE Linux Enterprise Server for SAP 12-SP2 | affected tomcat - < 8.0.53-29.32.1 |
SUSE | SUSE Linux Enterprise Server for SAP 12-SP3 | affected tomcat - < 8.0.53-29.32.1 |
SUSE | SUSE Linux Enterprise Server for SAP 15 | affected tomcat - < 9.0.35-3.57.3 |
SUSE | SUSE OpenStack Cloud 7 | affected tomcat - < 8.0.53-29.32.1 |
SUSE | SUSE OpenStack Cloud 8 | affected tomcat - < 8.0.53-29.32.1 |
SUSE | SUSE OpenStack Cloud Crowbar 8 | affected tomcat - < 8.0.53-29.32.1 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now