vulnerability

SUSE: CVE-2024-22029: SUSE Linux Security Advisory

Severity
7
CVSS
(AV:L/AC:L/Au:S/C:C/I:C/A:C)
Published
Feb 14, 2024
Added
Feb 15, 2024
Modified
Dec 5, 2025

Description

Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root

Solutions

suse-upgrade-tomcatsuse-upgrade-tomcat-admin-webappssuse-upgrade-tomcat-docs-webappsuse-upgrade-tomcat-el-3_0-apisuse-upgrade-tomcat-embedsuse-upgrade-tomcat-javadocsuse-upgrade-tomcat-jsp-2_3-apisuse-upgrade-tomcat-jsvcsuse-upgrade-tomcat-libsuse-upgrade-tomcat-servlet-4_0-apisuse-upgrade-tomcat-webappssuse-upgrade-tomcat10suse-upgrade-tomcat10-admin-webappssuse-upgrade-tomcat10-docsuse-upgrade-tomcat10-docs-webappsuse-upgrade-tomcat10-el-5_0-apisuse-upgrade-tomcat10-embedsuse-upgrade-tomcat10-jsp-3_1-apisuse-upgrade-tomcat10-jsvcsuse-upgrade-tomcat10-libsuse-upgrade-tomcat10-servlet-6_0-apisuse-upgrade-tomcat10-webapps
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.