PT-2016-1317 · Apache+5 · Apache Tomcat+5

Publicado

2016-02-08

·

Atualizado

2024-06-15

·

CVE-2016-0763

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 7.0.0 through 7.0.67 Apache Tomcat versions 8.0.0 through 8.0.30 Apache Tomcat versions 9.0.0.M1 through 9.0.0.M2
Description The issue is related to the setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java, which does not consider whether callers are authorized. This allows remote authenticated users to bypass intended SecurityManager restrictions and read or write to arbitrary application data, or cause a denial of service via a web application that sets a crafted global context. The issue only affects users running untrusted web applications under a security manager.
Recommendations For Apache Tomcat versions 7.0.0 through 7.0.67, update to version 7.0.68 or later. For Apache Tomcat versions 8.0.0 through 8.0.30, update to version 8.0.31 or later. For Apache Tomcat versions 9.0.0.M1 through 9.0.0.M2, update to version 9.0.0.M3 or later. As a temporary workaround, consider restricting access to the setGlobalContext method to minimize the risk of exploitation.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-1193
BDU:2016-00616
CESA-2016_2599
CVE-2016-0763
DLA-435-1
DSA-3530-1
DSA-3552-1
DSA-3609-1
GHSA-9HJV-9H75-XMPP
MGASA-2016-0090
OPENSUSE-SU-2016_0865-1
OPENSUSE-SU-2024:10446-1
OPENSUSE-SU-2024:13441-1
RHSA-2016:1087
RHSA-2016:1088
RHSA-2016:2599
RHSA-2016:2807
RHSA-2016_2599
SUSE-SU-2016:0769-1
SUSE-SU-2016:0822-1
USN-3024-1

Produtos afetados

Alt Linux
Apache Tomcat
Centos
Red Hat
Suse
Ubuntu