CVE-2024-22029 - CVE House
Back to Database
Status published High CVE-2024-22029

tomcat packaging allows for escalation to root from tomcat user

Vulnerability Description

Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-22029

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Johannes Segitz of SUSE

Affected Vendor

Affected Software

Container suse/manager/5.0/x86_64/server:5.0.0-beta1.2.122, SUSE Enterprise Storage 7.1, SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS, SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS, SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS, SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS, SUSE Linux Enterprise High Performance Computing 15 SP5, SUSE Linux Enterprise Module for Web and Scripting 15 SP5, SUSE Linux Enterprise Server 15 SP5, SUSE Linux Enterprise Server for SAP Applications 15 SP5, SUSE Linux Enterprise High Performance Computing 15 SP6, SUSE Linux Enterprise Module for Web and Scripting 15 SP6, SUSE Linux Enterprise Server 15 SP6, SUSE Linux Enterprise Server for SAP Applications 15 SP6, SUSE Linux Enterprise Server 15 SP2-LTSS, SUSE Linux Enterprise Server 15 SP3-LTSS, SUSE Linux Enterprise Server 15 SP4-LTSS, SUSE Linux Enterprise Server for SAP Applications 15 SP2, SUSE Linux Enterprise Server for SAP Applications 15 SP3, SUSE Linux Enterprise Server for SAP Applications 15 SP4, SUSE Manager Server 4.3, openSUSE Leap 15.5, openSUSE Tumbleweed
Vulnerable Versions:
?

Timeline

Official Publish: October 16th, 2024
Last Modified: August 26th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)