PT-2017-16643 · Apache+5 · Apache Tomcat+5

Publicado

2017-03-13

·

Atualizado

2024-06-15

·

CVE-2017-5648

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 9.0.0.M1 through 9.0.0.M17 Apache Tomcat versions 8.5.0 through 8.5.11 Apache Tomcat versions 8.0.0.RC1 through 8.0.41 Apache Tomcat versions 7.0.0 through 7.0.75
Description The issue arises from some calls to application listeners not using the appropriate facade object. When an untrusted application is run under a SecurityManager, it can retain a reference to the request or response object, allowing it to access and/or modify information associated with another web application.
Recommendations For Apache Tomcat versions 9.0.0.M1 through 9.0.0.M17, update to a version that uses the appropriate facade object for application listeners. For Apache Tomcat versions 8.5.0 through 8.5.11, update to a version that uses the appropriate facade object for application listeners. For Apache Tomcat versions 8.0.0.RC1 through 8.0.41, update to a version that uses the appropriate facade object for application listeners. For Apache Tomcat versions 7.0.0 through 7.0.75, update to a version that uses the appropriate facade object for application listeners. As a temporary workaround, consider restricting access to sensitive information when running untrusted applications under a SecurityManager.

Correção

Exposure of Resource to Wrong Sphere

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-2558
CESA-2017_1809
CVE-2017-5648
DLA-924-1
DSA-3842-1
DSA-3843-1
GHSA-3VX3-XF6Q-R5XP
MGASA-2017-0117
OPENSUSE-SU-2017_1292-1
OPENSUSE-SU-2024:11468-1
OPENSUSE-SU-2024:13441-1
RHSA-2017:1801
RHSA-2017:1809
RHSA-2017_1809
SUSE-SU-2017:1229-1
SUSE-SU-2017:1382-1
SUSE-SU-2017:1660-1
USN-3519-1

Produtos afetados

Alt Linux
Apache Tomcat
Centos
Red Hat
Suse
Ubuntu