Логотип exploitDog
bind:CVE-2016-6794
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2016-6794

Количество 12

Количество 12

ubuntu логотип

CVE-2016-6794

почти 8 лет назад

When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, 6.0.0 to 6.0.45 the system property replacement feature for configuration files could be used by a malicious web application to bypass the SecurityManager and read system properties that should not be visible.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2016-6794

больше 8 лет назад

When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, 6.0.0 to 6.0.45 the system property replacement feature for configuration files could be used by a malicious web application to bypass the SecurityManager and read system properties that should not be visible.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2016-6794

почти 8 лет назад

When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, 6.0.0 to 6.0.45 the system property replacement feature for configuration files could be used by a malicious web application to bypass the SecurityManager and read system properties that should not be visible.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2016-6794

почти 8 лет назад

When a SecurityManager is configured, a web application's ability to r ...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2rvf-329f-p99g

около 3 лет назад

System Property Disclosure in Apache Tomcat

CVSS3: 5.3
EPSS: Низкий
oracle-oval логотип

ELSA-2017-2247

почти 8 лет назад

ELSA-2017-2247: tomcat security, bug fix, and enhancement update (LOW)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2016:3144-1

больше 8 лет назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2016:3129-1

больше 8 лет назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:3081-1

больше 8 лет назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:3079-1

больше 8 лет назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:1632-1

почти 8 лет назад

Security update for tomcat6

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:1660-1

почти 8 лет назад

Security update for tomcat

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2016-6794

When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, 6.0.0 to 6.0.45 the system property replacement feature for configuration files could be used by a malicious web application to bypass the SecurityManager and read system properties that should not be visible.

CVSS3: 5.3
0%
Низкий
почти 8 лет назад
redhat логотип
CVE-2016-6794

When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, 6.0.0 to 6.0.45 the system property replacement feature for configuration files could be used by a malicious web application to bypass the SecurityManager and read system properties that should not be visible.

CVSS3: 3.1
0%
Низкий
больше 8 лет назад
nvd логотип
CVE-2016-6794

When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, 6.0.0 to 6.0.45 the system property replacement feature for configuration files could be used by a malicious web application to bypass the SecurityManager and read system properties that should not be visible.

CVSS3: 5.3
0%
Низкий
почти 8 лет назад
debian логотип
CVE-2016-6794

When a SecurityManager is configured, a web application's ability to r ...

CVSS3: 5.3
0%
Низкий
почти 8 лет назад
github логотип
GHSA-2rvf-329f-p99g

System Property Disclosure in Apache Tomcat

CVSS3: 5.3
0%
Низкий
около 3 лет назад
oracle-oval логотип
ELSA-2017-2247

ELSA-2017-2247: tomcat security, bug fix, and enhancement update (LOW)

почти 8 лет назад
suse-cvrf логотип
openSUSE-SU-2016:3144-1

Security update for tomcat

больше 8 лет назад
suse-cvrf логотип
openSUSE-SU-2016:3129-1

Security update for tomcat

больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2016:3081-1

Security update for tomcat

больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2016:3079-1

Security update for tomcat

больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:1632-1

Security update for tomcat6

почти 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:1660-1

Security update for tomcat

почти 8 лет назад

Уязвимостей на страницу