Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-6796

Опубликовано: 27 окт. 2016
Источник: redhat
CVSS3: 4.2
CVSS2: 4

Описание

A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via manipulation of the configuration parameters for the JSP Servlet.

It was discovered that a malicious web application could bypass a configured SecurityManager via manipulation of the configuration parameters for the JSP Servlet.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5tomcat5Will not fix
Red Hat Enterprise Linux 6tomcat6Will not fix
Red Hat JBoss BRMS 5jbosswebOut of support scope
Red Hat JBoss Data Grid 6jbosswebOut of support scope
Red Hat JBoss Data Virtualization 6jbosswebOut of support scope
Red Hat JBoss Enterprise Application Platform 5jbosswebOut of support scope
Red Hat JBoss Enterprise Web Server 2tomcat6Will not fix
Red Hat JBoss Enterprise Web Server 2tomcat7Will not fix
Red Hat JBoss Enterprise Web Server 3tomcat7Fix deferred
Red Hat JBoss Enterprise Web Server 3tomcat8Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=1390515tomcat: security manager bypass via JSP Servlet config parameters

4.2 Medium

CVSS3

4 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 8 лет назад

A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via manipulation of the configuration parameters for the JSP Servlet.

CVSS3: 7.5
nvd
около 8 лет назад

A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via manipulation of the configuration parameters for the JSP Servlet.

CVSS3: 7.5
debian
около 8 лет назад

A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0 ...

CVSS3: 7.5
github
больше 3 лет назад

Apache Tomcat vulnerable to SecurityManager bypass

oracle-oval
больше 8 лет назад

ELSA-2017-2247: tomcat security, bug fix, and enhancement update (LOW)

4.2 Medium

CVSS3

4 Medium

CVSS2