Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-7810

Опубликовано: 14 мая 2015
Источник: redhat
CVSS2: 5.8

Описание

The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypass a SecurityManager protection mechanism via a web application that leverages use of incorrect privileges during EL evaluation.

It was found that the expression language resolver evaluated expressions within a privileged code section. A malicious web application could use this flaw to bypass security manager protections.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6jbosswebNot affected
Red Hat Developer Toolset 2.1devtoolset-2-tomcatNot affected
Red Hat Enterprise Linux 5tomcat5Under investigation
Red Hat JBoss BRMS 6jbosswebNot affected
Red Hat JBoss Data Grid 6jbosswebUnder investigation
Red Hat JBoss Data Virtualization 6jbosswebNot affected
Red Hat JBoss Enterprise Application Platform 6jbosswebAffected
Red Hat JBoss Enterprise Web Server 1tomcat6Affected
Red Hat JBoss Fuse Service Works 6jbosswebNot affected
Red Hat JBoss Operations Network 3jbosswebUnder investigation

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1222573Tomcat/JbossWeb: security manager bypass via EL expressions

5.8 Medium

CVSS2

Связанные уязвимости

ubuntu
около 10 лет назад

The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypass a SecurityManager protection mechanism via a web application that leverages use of incorrect privileges during EL evaluation.

nvd
около 10 лет назад

The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypass a SecurityManager protection mechanism via a web application that leverages use of incorrect privileges during EL evaluation.

debian
около 10 лет назад

The Expression Language (EL) implementation in Apache Tomcat 6.x befor ...

suse-cvrf
около 10 лет назад

Security update for tomcat

github
около 3 лет назад

Improper Access Control in Apache Tomcat

5.8 Medium

CVSS2