PT-2016-1317 · Apache+5 · Apache Tomcat+5
Published
2016-02-08
·
Updated
2024-06-15
·
CVE-2016-0763
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Apache Tomcat versions 7.0.0 through 7.0.67
Apache Tomcat versions 8.0.0 through 8.0.30
Apache Tomcat versions 9.0.0.M1 through 9.0.0.M2
Description
The issue is related to the setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java, which does not consider whether callers are authorized. This allows remote authenticated users to bypass intended SecurityManager restrictions and read or write to arbitrary application data, or cause a denial of service via a web application that sets a crafted global context. The issue only affects users running untrusted web applications under a security manager.
Recommendations
For Apache Tomcat versions 7.0.0 through 7.0.67, update to version 7.0.68 or later.
For Apache Tomcat versions 8.0.0 through 8.0.30, update to version 8.0.31 or later.
For Apache Tomcat versions 9.0.0.M1 through 9.0.0.M2, update to version 9.0.0.M3 or later.
As a temporary workaround, consider restricting access to the setGlobalContext method to minimize the risk of exploitation.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Apache Tomcat
Centos
Red Hat
Suse
Ubuntu