VMware ESX Server 3.0.3, ESX303-200808407-SG: Security Updates to Web Access Components Tomcat and JRE (1006358)
Summaries and Symptoms
Web Access component Apache Tomcat updated to version 5.5.26.
The currently installed version of Tomcat depends on your patch deployment history.
For more information about security issues fixed in version 5.5.26 and in earlier versions and their CVE identifiers, see the Apache Tomcat 5.x Vulnerabilities page at http://tomcat.apache.org/security-5.
Web Access component JRE updated to version 1.5.0_15.
The currently installed version of JRE depends on your patch deployment history.
For more information about security issues fixed in version 1.5.0_15 and in earlier versions, see the JRE release notes at http://java.sun.com/j2se/1.5.0/ReleaseNotes.
The following advisories by Secunia list the CVE identifiers related to the fixed security issues in JRE 1.5.0_12, JRE 1.5.0_13, JRE 1.5.0_14, and JRE 1.5.0_15:
Log in to the service console as root.
Run the command:
service vmware-webAccess restart
Patch Download and Installation
See the VMware Update Manager Administration Guide for instructions on using VMware Update Manager to download and install patches to automatically update ESX Server 3.0.3 hosts.
To update ESX Server 3.0.3 hosts when not using VMware Update Manager, download the most recent patch bundle from http://support.vmware.com/selfsupport/download/ and install the bundle using esxupdate from the command line of the host. For more information, see the ESX Server 3 Patch Management Guide .