Описание
The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global JNDI resources to those resources explicitly linked to the web application. Therefore, it was possible for a web application to access any global JNDI resource whether an explicit ResourceLink had been configured or not.
It was discovered that it was possible for a web application to access any global JNDI resource whether an explicit ResourceLink had been configured or not.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | tomcat5 | Will not fix | ||
Red Hat Enterprise Linux 6 | tomcat6 | Will not fix | ||
Red Hat JBoss BRMS 5 | jbossweb | Out of support scope | ||
Red Hat JBoss Data Grid 6 | jbossweb | Out of support scope | ||
Red Hat JBoss Data Virtualization 6 | jbossweb | Out of support scope | ||
Red Hat JBoss Enterprise Application Platform 5 | jbossweb | Not affected | ||
Red Hat JBoss Enterprise Application Platform 6 | jbossweb | Not affected | ||
Red Hat JBoss Enterprise Web Server 2 | tomcat6 | Will not fix | ||
Red Hat JBoss Enterprise Web Server 2 | tomcat7 | Will not fix | ||
Red Hat JBoss Enterprise Web Server 3 | tomcat7 | Fix deferred |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
3.7 Low
CVSS3
2.6 Low
CVSS2
Связанные уязвимости
The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global JNDI resources to those resources explicitly linked to the web application. Therefore, it was possible for a web application to access any global JNDI resource whether an explicit ResourceLink had been configured or not.
The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global JNDI resources to those resources explicitly linked to the web application. Therefore, it was possible for a web application to access any global JNDI resource whether an explicit ResourceLink had been configured or not.
The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9. ...
ELSA-2017-2247: tomcat security, bug fix, and enhancement update (LOW)
EPSS
3.7 Low
CVSS3
2.6 Low
CVSS2