<div class="container">
    <h1>Security update for tomcat11</h1>

    <table class="table table-striped table-bordered">
        <tbody>
        <tr>
            <th>Announcement ID:</th>
            <td>SUSE-SU-2026:22648-1</td>
        </tr>
        <tr>
            <th>Release Date:</th>
            <td>2026-07-13T16:24:32Z</td>
        </tr>
        
        <tr>
            <th>Rating:</th>
            <td>moderate</td>
        </tr>
        <tr>
            <th>References:</th>
            <td>
                <ul>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1232390">bsc#1232390</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1269791">bsc#1269791</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1269824">bsc#1269824</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1269907">bsc#1269907</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1269908">bsc#1269908</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1269909">bsc#1269909</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1269910">bsc#1269910</a>
                        </li>
                    
                    
                </ul>
            </td>
        </tr>
        
            <tr>
                <th>
                    Cross-References:
                </th>
                <td>
                    <ul>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2026-50229.html">CVE-2026-50229</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2026-53404.html">CVE-2026-53404</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2026-53434.html">CVE-2026-53434</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2026-55276.html">CVE-2026-55276</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2026-55955.html">CVE-2026-55955</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2026-55956.html">CVE-2026-55956</a>
                        </li>
                    
                    </ul>
                </td>
            </tr>
            <tr>
                <th>CVSS scores:</th>
                <td>
                    <ul class="list-group">
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-50229</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">5.3</span>
                                <span class="cvss-vector">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-50229</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">6.1</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-50229</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">6.1</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-53404</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">6.9</span>
                                <span class="cvss-vector">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-53404</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">6.5</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-53404</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">7.3</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-53434</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">6.9</span>
                                <span class="cvss-vector">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-53434</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">6.5</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-53434</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">9.1</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-55276</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">4.8</span>
                                <span class="cvss-vector">CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-55276</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">3.3</span>
                                <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-55276</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">9.1</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-55955</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">2.3</span>
                                <span class="cvss-vector">CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-55955</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">4.2</span>
                                <span class="cvss-vector">CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-55955</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">6.5</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-55956</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">6.9</span>
                                <span class="cvss-vector">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-55956</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">6.5</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-55956</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">6.5</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</span>
                            </li>
                        
                    </ul>
                </td>
            </tr>
        
        <tr>
            <th>Affected Products:</th>
            <td>
                <ul class="list-group">
                    
                        <li class="list-group-item">SUSE Linux Enterprise Server 16.0</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise Server for SAP applications 16.0</li>
                    
                </ul>
            </td>
        </tr>
        </tbody>
    </table>

    <p>An update that solves six vulnerabilities and has one fix can now be installed.</p>

    


    
        <h2>Description:</h2>
    
    <p>This update for tomcat11 fixes the following issues</p>
<p>Update to Tomcat 11.0.23.</p>
<p>Security issues fixed:</p>
<ul>
<li>CVE-2026-50229: improper neutralization of script-related HTML tags in the number guess example (bsc#1269791).</li>
<li>CVE-2026-53404: always-incorrect control flow implementation in the rewrite valve caused non-OR conditions to be
  skipped if the first condition in an OR chain matched (bsc#1269910).</li>
<li>CVE-2026-53434: error condition not handled when configuring CRLs for a FFM based connector (bsc#1269824).</li>
<li>CVE-2026-55276: always-incorrect control flow implementation caused special roles and empty authorization constraints
  to not be included when the effective web.xml was logged (bsc#1269909).</li>
<li>CVE-2026-55955: improper authentication allows a replay attack against the EncryptionInterceptor in the cluster
  component (bsc#1269908).</li>
<li>CVE-2026-55956: improper authorization leads to security constraints specified for the default servlet ignoring any
  method or method omission configured as part of the constraint (bsc#1269907).</li>
</ul>
<p>Other updates and bugfixes:</p>
<ul>
<li>Upgrade libtcnative to v2 (bsc#1232390)</li>
<li>Tomcat 11.0.23:</li>
<li>Catalina<ul>
<li>Add: Add support for literal &#x27;%&#x27; characters in access log output. Based on
  pull request #1002 by Fabian Hahn. (markt)</li>
<li>Fix: Lower the log level to debug when OpenSSL initialization fails in
  OpenSSLLifecycleListener to avoid stack traces when libssl.so is not
  present and to align the behavior of the isAvailable() check with the
  AprLifecycleListener and gracefully fail when natives are not present.
  (csutherl)</li>
<li>Fix: 70038: Cookie.clone() should also clone the internal attribute map.
  (markt)</li>
<li>Code: Remove unnecessary code from the SSI processing engine that was
  duplicating some of the normalisation checks. (markt)</li>
<li>Fix: Cleaner handling of invalid SPNEGO tokens. (remm)</li>
<li>Fix: Avoid some NPEs in the Connector class on an uninitialize protocol.
  (remm)</li>
<li>Fix: Incorrect session average life calculation. (remm)</li>
<li>Fix: Improve robustness on using Pipeline.setBasic on a running pipeline.
  (remm)</li>
<li>Fix: Avoid any init parameter updates when conflicts are found for
  filters, similar to what is done for servlets, as required by the servlet
  specification. (remm)</li>
<li>Fix: Fix container event cleanups in some edge cases. (remm)</li>
<li>Fix: Check for last-modified header in ExpiresFilter when a servlet uses
  addDateHeader to avoid wrongly considering it has been set. (remm)</li>
<li>Fix: Fix hour unit used by ExpiresFilter. (remm)</li>
<li>Fix: Remove exception swallowing in DataSourceStore to align it with
  FileStore and avoid session loss on errors. (remm)</li>
<li>Fix: Add support for single-quote escaped literal as well as quoted
  literals in DateFormatCache. (schultz)</li>
<li>Fix: On JAAS logout, clear out role principals on the subject that were
  added on commit, as recommended by the JAAS specification. (remm)</li>
<li>Fix: MemoryRealm should not add a dummy role when none is specified in the
  configuration. (remm)</li>
<li>Fix: DataSourceUserDatabase should return a null principal on a non
  existing user. (remm)</li>
<li>Fix: Fix shared lock expiration in WebDAV. (remm)</li>
<li>Fix: Inaccurate session exipration statistics when using the persistent
  manager. (remm)</li>
<li>Fix: Skip BOM when serving files with UTF-32 encoding. (remm)</li>
<li>Fix: Mixup of WrapperListener and WrapperLifecycle elements in
  storeconfig. (remm)</li>
<li>Fix: Incorrect processing of modified users in DataSourceUserDatabase.
  (remm)</li>
<li>Update: Clarify behavior in the UserDatabase for user, role and group
  creation that it does not immediately override existing elements. Removal
  (or update) needs to be used instead. (remm)</li>
<li>Fix: 70049: Align the web application class loader with parent class
  loaders and swallow any errors caused by invalid paths when looking up
  resources and behave as if the resources were not found in that case.
  (markt)</li>
<li>Fix: Improve validation of Range and Content-Range parsers so invalid
  ranges trigger a 4xx response rather than a 500 response. Pull request
  #1012 provided by Sahana Surendra Bogar. (markt)</li>
<li>Fix: Fix connection leak in ProxyErrorReportValve. (remm)</li>
<li>Fix: When using the RewriteValve, %{SSL:HTTPS} now returns on or off
  rather than true or false to align with httpd. (markt)</li>
<li>Fix: Reset the encoding used for query string parameters between requests
  in case an application changed the encoding in a previous request. (markt)</li>
<li>Fix: When encoding URLs with the CsrfPreventionFilter, don&#x27;t add the nonce
  to URLs that are known not to require it. (markt)</li>
<li>Fix: Fix SSO cookie partitioned configuration. (remm)</li>
<li>Fix: Fix CombinedRealm isAvailable, it allows authentication if at least
  one sub realm is available. (remm)</li>
<li>Fix: 70048: Correctly handle asynchronous requests in PersistentValve.
  (markt)</li>
<li>Fix: Improve the detection of cross-context dispatches when using a
  RequestDispatcher. (markt)</li>
<li>Fix: Fix various instances of double decoding of URL patterns configured
  either programmatically or in web.xml. (remm/markt)</li>
<li>Fix: Align the rewrite conditions ornext flag processing with mod_rewrite,
  which follows a purely sequential evaluation strategy. (remm)</li>
<li>Fix: Update default web.xml version to match supported Servlet
  specification version. (markt)</li>
<li>Fix: Change the default for the useRedirect attribute of the
  ProxyErrorReportValve from true to false. (markt)</li>
<li>Add: Add support for the showReport attribute in JsonErrorReportValve and
  ProxyErrorReportValve. When set to false, detailed error information
  (message, description, stack trace) is suppressed from error responses.
  (dsoumis)</li>
<li>Fix: Avoid a NoClassDefFoundError at startup when catalina-tribes.jar is
  removed but catalina-ha.jar is present and the Cluster element is enabled
  in server.xml. Cluster digester rules are now fully conditional on both
  JARs being available. (dsoumis)</li>
<li>Fix: Fix a potential deadlock when copying resources using WebDAV. (markt)</li>
<li>Fix: Add jakarta., org.apache.catalina. and org.apache.tomcat.to the list
  of reserved prefixes for SSI variables and request attributes. (markt)</li>
<li>Fix: Missing URL decoding when processing addMapping on a Servlet
  registration. (remm)</li>
<li>Fix: The Timeout WebDAV header allows comma separated values (according to
  the examples in the RFC). Use the first acceptable value. (remm)</li>
<li>Fix: Fix various issues when logging the effective web.xml for a web
  application. Empty sections are no longer logged. Special roles and empty
  authorisation constraints are included. All session cookie attributes are
  included. (markt)</li>
<li>Fix: Expand the write lock for the save process in the MemoryUserDatabase
  to avoid concurrency issues with the file save operations. (markt)</li>
<li>Fix: Ensure atomic session persistence in FileStore. Based on pull request
  #1016 by sahvx655-wq. (markt)</li>
<li>Fix: Do not ignore methods configured on security constraints that map to
  the default servlet. (markt)</li>
</ul>
</li>
<li>Cluster<ul>
<li>Fix: Expand wording and increase visibility of log message when cloud
  membership is configured without a trust store as all certificates will be
  trusted in this configuration. (markt)</li>
<li>Fix: Ensure listeners are correctly added and removed when configuring the
  channel coordinator. (markt)</li>
<li>Fix: Fix some concurrency issues in FragmentationInterceptor. (markt)</li>
<li>Fix: Fix some concurrency issues in OrderInterceptor. (markt)</li>
<li>Fix: Fix some concurrency issues in TwoPhaseCommitInterceptor. (markt)</li>
<li>Fix: Fix concurrency issues generating MD5 digests in the
  CloudMembershipProvider implementations. (markt)</li>
<li>Add: Add replay protection to the EncryptInterceptor. This us a breaking
  change for the EncryptInterceptor.(markt)</li>
</ul>
</li>
<li>Coyote<ul>
<li>Add: Log a suitable warning if an encrypted PEM file is detected using an
  insecure form for encryption. (markt)</li>
<li>Fix: If TLS groups have been configured, use the configured groups rather
  than using OpenSSL&#x27;s default TLS groups when using Tomcat Native with
  OpenSSL based connectors. (markt)</li>
<li>Fix: For HTTP/2, ensure that any in progress request body reads are
  cancelled if the container resets the associated stream. This prevents
  delays waiting for reads to time out when it is known that no more data
  will be received. (markt)</li>
<li>Fix: Ensure that malformed HTTP/2 messages that should trigger a stream
  reset do so, rather than triggered a connection close. (markt)</li>
<li>Fix: Improve enforcement of header trailer allow list for HTTP/2. (remm)</li>
<li>Fix: 70050: Avoid NPE when no header frame is processed in HTTP/2,
  following refactor clean-up of header buffer. (remm)</li>
<li>Fix: Properly use pollerThreadPriority for the NIO poller thread. (remm)</li>
<li>Fix: Fix MessageByte.equals if called on a null MB. (remm)</li>
<li>Fix: Call the delegate key manager in JSSE to retrieve the server key.
  (remm)</li>
<li>Fix: Avoid overflow scenarios in Asn1Parser. (remm)</li>
<li>Fix: 70091: Add a new attribute, allowSchemeMismatch to Http2Protocol that
  allows the consistency check for the scheme provided by the user agent to
  be bypassed. (markt)</li>
<li>Fix: isTrailerFieldsReady was always returning true. (remm)</li>
<li>Fix: Align OpenSSL/Panama TLS implementation with other implementations
  and throw an exception if there is an error loading the provided CRL(s).
  (markt)</li>
<li>Fix: Parsing of OpenSSL format cipher expressions incorrectly stopped if
  @STRENGTH was encountered, ignoring any subsequent expressions. (markt)</li>
<li>Fix: Handle the case where the HTTP/2 payload length is insufficient for
  the mandatory data required by the flags set in the header. (markt)</li>
<li>Fix: 70102: Correct expected size of ticket keys when calling
  setSessionTicketKeys with an FFM connector. (markt)</li>
<li>Fix: 69988: Fix post handshake authentication for TLS 1.3. It was broken
  by a breaking change in OpenSSL between 1.1.1 and 3.0.0. (markt)</li>
<li>Fix: When processing an OpenSSL cipher specification, fully align the
  order of the resulting ciphers with the order produced by OpenSSL. (markt)</li>
<li>Add: Add support for Brainpool TLS groups. Patch provided by YStankov.
  (schultz)</li>
<li>Update: Update both the minimum and recommended version for Tomcat Native
  2.x to 2.0.15. (markt)</li>
<li>Update: Update the minimum version for Tomcat Native 1.x to 1.3.8. (markt)</li>
</ul>
</li>
<li>Jasper<ul>
<li>Fix: Fix possible EL argument mismatch when it was set to null. (remm)</li>
<li>Fix: Fix thread safety of TagPluginManager. (remm)</li>
<li>Fix: Correctly use flush on JSP include. (remm)</li>
</ul>
</li>
<li>Web applications<ul>
<li>Add: Manager: Add checks to ensure that any uploaded files are uploaded to
  the expected location. (markt)</li>
<li>Add: Manager: Add checks to ensure that the requested context path for a
  deployed WAR, directory or descriptor file is valid. (markt)</li>
<li>Add: Documentation: Expand the description of some of the attributes of
  the CrawlerSessionManagerValve. (markt)</li>
<li>Fix: Documentation: Clearer description and correct documented default for
  ocspSoftFail. (markt)</li>
<li>Fix: Fix double escaping in the context names for the JSON mode of the
  manager servlet. (remm)</li>
<li>Fix: Manager: Ensure automatic deployment does not trigger an undeployment
  during a Manager triggered web application reload. (markt)</li>
<li>Fix: Documentation: Provide better documentation for the scheme and secure
  attributes of a Connector. (markt)</li>
</ul>
</li>
<li>Websocket<ul>
<li>Fix: Incorrect Future.isDone() return by AsyncChannelWrapperSecure. (remm)</li>
<li>Fix: Trigger standard WebSocket error handling if a call to
  Endpoint.onOpen() fails for a programmatic endpoint. (markt)</li>
<li>Fix: 70110: Fix memory leak if a call to Endpoint.onOpen() fails for a
  programmatic endpoint. Test case provided by uabdur. (markt)</li>
<li>Fix: If a client presents invalid parameters when negotiating a WebSocket
  extension, decline the negotiation offer that includes the invalid
  parameters rather than failing the connection. Pull request #1019 provided
  by sahvx655-wq. (markt)</li>
</ul>
</li>
<li>Other<ul>
<li>Fix: Use per connection authenticator when executing an Ant task.
  (remm/markt)</li>
<li>Update: Update Commons Daemon to 1.6.1. (markt)</li>
<li>Fix: Prevent duplicate log messages when clustering JARs are not present
  on startup. (csutherl)</li>
<li>Update: Improvements to French translations. (remm)</li>
<li>Update: Improvements to Japanese translations provided by tak7iji. (markt)</li>
<li>Update: Update the packaged version of the Tomcat Migration Tool for
  Jakarta EE to 1.0.12. (markt)</li>
<li>Update: Update Tomcat Native to 2.0.15. (markt)</li>
</ul>
</li>
</ul>



    

    <h2>Patch Instructions:</h2>
    <p>
        To install this SUSE  update use the SUSE recommended
        installation methods like YaST online_update or "zypper patch".<br/>

        Alternatively you can run the command listed for your product:
    </p>
    <ul class="list-group">
        
            <li class="list-group-item">
                SUSE Linux Enterprise Server 16.0
                
                    
                        <br/>
                        <code>zypper in -t patch SUSE-SLES-16.0-1233=1</code>
                    
                    
                
            </li>
        
            <li class="list-group-item">
                SUSE Linux Enterprise Server for SAP applications 16.0
                
                    
                        <br/>
                        <code>zypper in -t patch SUSE-SLES-16.0-1233=1</code>
                    
                    
                
            </li>
        
    </ul>

    <h2>Package List:</h2>
    <ul>
        
            
                <li>
                    SUSE Linux Enterprise Server 16.0 (noarch)
                    <ul>
                        
                            <li>tomcat11-doc-11.0.23-160000.1.1</li>
                        
                            <li>tomcat11-11.0.23-160000.1.1</li>
                        
                            <li>tomcat11-embed-11.0.23-160000.1.1</li>
                        
                            <li>tomcat11-jsvc-11.0.23-160000.1.1</li>
                        
                            <li>tomcat11-docs-webapp-11.0.23-160000.1.1</li>
                        
                            <li>tomcat11-webapps-11.0.23-160000.1.1</li>
                        
                            <li>tomcat11-jsp-4_0-api-11.0.23-160000.1.1</li>
                        
                            <li>tomcat11-lib-11.0.23-160000.1.1</li>
                        
                            <li>tomcat11-el-6_0-api-11.0.23-160000.1.1</li>
                        
                            <li>tomcat11-admin-webapps-11.0.23-160000.1.1</li>
                        
                            <li>tomcat11-servlet-6_1-api-11.0.23-160000.1.1</li>
                        
                    </ul>
                </li>
            
        
            
                <li>
                    SUSE Linux Enterprise Server for SAP applications 16.0 (noarch)
                    <ul>
                        
                            <li>tomcat11-doc-11.0.23-160000.1.1</li>
                        
                            <li>tomcat11-embed-11.0.23-160000.1.1</li>
                        
                            <li>tomcat11-jsvc-11.0.23-160000.1.1</li>
                        
                            <li>tomcat11-webapps-11.0.23-160000.1.1</li>
                        
                            <li>tomcat11-docs-webapp-11.0.23-160000.1.1</li>
                        
                            <li>tomcat11-jsp-4_0-api-11.0.23-160000.1.1</li>
                        
                            <li>tomcat11-el-6_0-api-11.0.23-160000.1.1</li>
                        
                            <li>tomcat11-lib-11.0.23-160000.1.1</li>
                        
                            <li>tomcat11-11.0.23-160000.1.1</li>
                        
                            <li>tomcat11-admin-webapps-11.0.23-160000.1.1</li>
                        
                            <li>tomcat11-servlet-6_1-api-11.0.23-160000.1.1</li>
                        
                    </ul>
                </li>
            
        
    </ul>

    
        <h2>References:</h2>
        <ul>
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2026-50229.html">https://www.suse.com/security/cve/CVE-2026-50229.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2026-53404.html">https://www.suse.com/security/cve/CVE-2026-53404.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2026-53434.html">https://www.suse.com/security/cve/CVE-2026-53434.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2026-55276.html">https://www.suse.com/security/cve/CVE-2026-55276.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2026-55955.html">https://www.suse.com/security/cve/CVE-2026-55955.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2026-55956.html">https://www.suse.com/security/cve/CVE-2026-55956.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1232390">https://bugzilla.suse.com/show_bug.cgi?id=1232390</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1269791">https://bugzilla.suse.com/show_bug.cgi?id=1269791</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1269824">https://bugzilla.suse.com/show_bug.cgi?id=1269824</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1269907">https://bugzilla.suse.com/show_bug.cgi?id=1269907</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1269908">https://bugzilla.suse.com/show_bug.cgi?id=1269908</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1269909">https://bugzilla.suse.com/show_bug.cgi?id=1269909</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1269910">https://bugzilla.suse.com/show_bug.cgi?id=1269910</a>
                    </li>
                
            
        </ul>
    
</div>