PT-2016-6828 · Apache+2 · Apache Tomcat+4

Tomas Hoger

·

Publicado

2016-10-10

·

Atualizado

2023-02-12

·

CVE-2016-6325

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tomcat package on Red Hat Enterprise Linux (RHEL) versions 5 through 7 JBoss Web Server version 3.0 JBoss EWS version 2
Description The issue is related to weak permissions for certain configuration files, specifically (1) /etc/sysconfig/tomcat and (2) /etc/tomcat/tomcat.conf. This weakness allows local users to gain privileges by leveraging membership in the tomcat group.
Recommendations For Tomcat package on Red Hat Enterprise Linux (RHEL) versions 5 through 7, consider restricting access to the /etc/sysconfig/tomcat and /etc/tomcat/tomcat.conf files to prevent local users from gaining privileges. For JBoss Web Server version 3.0, restrict access to the /etc/sysconfig/tomcat and /etc/tomcat/tomcat.conf files to minimize the risk of exploitation. For JBoss EWS version 2, restrict access to the /etc/sysconfig/tomcat and /etc/tomcat/tomcat.conf files to prevent local users from gaining privileges.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CESA-2016_2045
CESA-2016_2046
CVE-2016-6325
MGASA-2016-0367
RHSA-2016:2045
RHSA-2016:2046
RHSA-2016_2045
RHSA-2016_2046
RHSA-2017:0455
RHSA-2017:0456

Produtos afetados

Centos
Jbossws
Jboss Web Server
Red Hat
Apache Tomcat