PT-2016-1316 · Apache+5 · Apache Tomcat+5

Publicado

2016-02-08

·

Atualizado

2024-06-15

·

CVE-2016-0714

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 6.x before 6.0.45 Apache Tomcat versions 7.x before 7.0.68 Apache Tomcat versions 8.x before 8.0.31 Apache Tomcat versions 9.x before 9.0.0.M2
Description The issue is related to the session-persistence implementation in Apache Tomcat, which mishandles session attributes. This allows remote authenticated users to bypass intended SecurityManager restrictions and execute arbitrary code in a privileged context via a web application that places a crafted object in a session. The problem affects users running untrusted web applications under a security manager. All session persistence mechanisms, including StandardManager, PersistentManager, and cluster implementation, could be exploited to bypass a security manager.
Recommendations For Apache Tomcat versions 6.x before 6.0.45, update to version 6.0.45 or later. For Apache Tomcat versions 7.x before 7.0.68, update to version 7.0.68 or later. For Apache Tomcat versions 8.x before 8.0.31, update to version 8.0.31 or later. For Apache Tomcat versions 9.x before 9.0.0.M2, update to version 9.0.0.M2 or later. As a temporary workaround, consider restricting access to untrusted web applications under a security manager until the issue is resolved.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-1193
BDU:2016-00615
CESA-2016_2045
CESA-2016_2599
CVE-2016-0714
DLA-435-1
DSA-3530-1
DSA-3552-1
DSA-3609-1
GHSA-MV42-PX54-87JW
MGASA-2016-0090
OPENSUSE-SU-2016_0865-1
OPENSUSE-SU-2024:10446-1
OPENSUSE-SU-2024:13441-1
RHSA-2016:1087
RHSA-2016:1088
RHSA-2016:2045
RHSA-2016:2599
RHSA-2016:2807
RHSA-2016_2045
RHSA-2016_2599
SUSE-SU-2016:0769-1
SUSE-SU-2016:0822-1
SUSE-SU-2016:0839-1
USN-3024-1

Produtos afetados

Alt Linux
Apache Tomcat
Centos
Red Hat
Suse
Ubuntu