PT-2016-1317 · Apache+5 · Apache Tomcat+5
Publicado
2016-02-08
·
Atualizado
2024-06-15
·
CVE-2016-0763
CVSS v2.0
6.5
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Apache Tomcat versions 7.0.0 through 7.0.67
Apache Tomcat versions 8.0.0 through 8.0.30
Apache Tomcat versions 9.0.0.M1 through 9.0.0.M2
Description
The issue is related to the setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java, which does not consider whether callers are authorized. This allows remote authenticated users to bypass intended SecurityManager restrictions and read or write to arbitrary application data, or cause a denial of service via a web application that sets a crafted global context. The issue only affects users running untrusted web applications under a security manager.
Recommendations
For Apache Tomcat versions 7.0.0 through 7.0.67, update to version 7.0.68 or later.
For Apache Tomcat versions 8.0.0 through 8.0.30, update to version 8.0.31 or later.
For Apache Tomcat versions 9.0.0.M1 through 9.0.0.M2, update to version 9.0.0.M3 or later.
As a temporary workaround, consider restricting access to the setGlobalContext method to minimize the risk of exploitation.
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Apache Tomcat
Centos
Red Hat
Suse
Ubuntu