Описание
The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 uses weak permissions for (1) /etc/sysconfig/tomcat and (2) /etc/tomcat/tomcat.conf, which allows local users to gain privileges by leveraging membership in the tomcat group.
It was discovered that the Tomcat packages installed certain configuration files read by the Tomcat initialization script as writeable to the tomcat group. A member of the group or a malicious web application deployed on Tomcat could use this flaw to escalate their privileges.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | tomcat5 | Will not fix | ||
Red Hat JBoss Enterprise Web Server 2 | tomcat | Will not fix | ||
Red Hat JBoss Enterprise Web Server 3 | tomcat | Fix deferred | ||
Red Hat Enterprise Linux 6 | tomcat6 | Fixed | RHSA-2016:2045 | 10.10.2016 |
Red Hat Enterprise Linux 7 | tomcat | Fixed | RHSA-2016:2046 | 10.10.2016 |
Red Hat JBoss Web Server 3.1 | Fixed | RHSA-2017:0457 | 07.03.2017 | |
Red Hat JBoss Web Server 3 for RHEL 6 | hibernate4-eap6 | Fixed | RHSA-2017:0455 | 07.03.2017 |
Red Hat JBoss Web Server 3 for RHEL 6 | jbcs-httpd24 | Fixed | RHSA-2017:0455 | 07.03.2017 |
Red Hat JBoss Web Server 3 for RHEL 6 | jbcs-httpd24-apache-commons-daemon | Fixed | RHSA-2017:0455 | 07.03.2017 |
Red Hat JBoss Web Server 3 for RHEL 6 | jbcs-httpd24-apache-commons-daemon-jsvc | Fixed | RHSA-2017:0455 | 07.03.2017 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.8 High
CVSS3
6.9 Medium
CVSS2
Связанные уязвимости
The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 uses weak permissions for (1) /etc/sysconfig/tomcat and (2) /etc/tomcat/tomcat.conf, which allows local users to gain privileges by leveraging membership in the tomcat group.
The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 uses weak permissions for (1) /etc/sysconfig/tomcat and (2) /etc/tomcat/tomcat.conf, which allows local users to gain privileges by leveraging membership in the tomcat group.
The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBo ...
The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 uses weak permissions for (1) /etc/sysconfig/tomcat and (2) /etc/tomcat/tomcat.conf, which allows local users to gain privileges by leveraging membership in the tomcat group.
EPSS
7.8 High
CVSS3
6.9 Medium
CVSS2