Количество 10
Количество 10
BDU:2016-00616
Уязвимость сервера приложений Apache Tomcat, позволяющая нарушителю вызвать отказ в обслуживании
CVE-2016-0763
The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLinkFactory.setGlobalContext callers are authorized, which allows remote authenticated users to bypass intended SecurityManager restrictions and read or write to arbitrary application data, or cause a denial of service (application disruption), via a web application that sets a crafted global context.
CVE-2016-0763
The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLinkFactory.setGlobalContext callers are authorized, which allows remote authenticated users to bypass intended SecurityManager restrictions and read or write to arbitrary application data, or cause a denial of service (application disruption), via a web application that sets a crafted global context.
CVE-2016-0763
The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLinkFactory.setGlobalContext callers are authorized, which allows remote authenticated users to bypass intended SecurityManager restrictions and read or write to arbitrary application data, or cause a denial of service (application disruption), via a web application that sets a crafted global context.
CVE-2016-0763
The setGlobalContext method in org/apache/naming/factory/ResourceLinkF ...
GHSA-9hjv-9h75-xmpp
Improper Verification of Source of a Communication Channel in Apache Tomcat
openSUSE-SU-2016:0865-1
Security update for tomcat
SUSE-SU-2016:0822-1
Security update for tomcat
SUSE-SU-2016:0769-1
Security update for tomcat
ELSA-2016-2599
ELSA-2016-2599: tomcat security, bug fix, and enhancement update (MODERATE)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2016-00616 Уязвимость сервера приложений Apache Tomcat, позволяющая нарушителю вызвать отказ в обслуживании | CVSS2: 6.5 | 0% Низкий | почти 10 лет назад | |
CVE-2016-0763 The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLinkFactory.setGlobalContext callers are authorized, which allows remote authenticated users to bypass intended SecurityManager restrictions and read or write to arbitrary application data, or cause a denial of service (application disruption), via a web application that sets a crafted global context. | CVSS3: 6.3 | 0% Низкий | почти 10 лет назад | |
CVE-2016-0763 The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLinkFactory.setGlobalContext callers are authorized, which allows remote authenticated users to bypass intended SecurityManager restrictions and read or write to arbitrary application data, or cause a denial of service (application disruption), via a web application that sets a crafted global context. | CVSS3: 6.3 | 0% Низкий | почти 10 лет назад | |
CVE-2016-0763 The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLinkFactory.setGlobalContext callers are authorized, which allows remote authenticated users to bypass intended SecurityManager restrictions and read or write to arbitrary application data, or cause a denial of service (application disruption), via a web application that sets a crafted global context. | CVSS3: 6.3 | 0% Низкий | почти 10 лет назад | |
CVE-2016-0763 The setGlobalContext method in org/apache/naming/factory/ResourceLinkF ... | CVSS3: 6.3 | 0% Низкий | почти 10 лет назад | |
GHSA-9hjv-9h75-xmpp Improper Verification of Source of a Communication Channel in Apache Tomcat | CVSS3: 6.3 | 0% Низкий | больше 3 лет назад | |
openSUSE-SU-2016:0865-1 Security update for tomcat | почти 10 лет назад | |||
SUSE-SU-2016:0822-1 Security update for tomcat | почти 10 лет назад | |||
SUSE-SU-2016:0769-1 Security update for tomcat | почти 10 лет назад | |||
ELSA-2016-2599 ELSA-2016-2599: tomcat security, bug fix, and enhancement update (MODERATE) | около 9 лет назад |
Уязвимостей на страницу