SB2018022023 - Amazon Linux AMI update for tomcat8



SB2018022023 - Amazon Linux AMI update for tomcat8

Published: February 20, 2018

Security Bulletin ID SB2018022023
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Security features (CVE-ID: CVE-2017-15706)

The vulnerability allows a remote attacker to write arbitrary files on the target system.

The weakness exists due to some scripts may have failed to execute as expected and other scripts may have been executed unexpectedly. A remote attacker can write arbitrary files.

Remediation

Install update from vendor's website.