PT-2016-6422 · Apache+2 · Apache Tomcat+2

Dawid Golunski

·

Published

2016-10-10

·

Updated

2023-02-12

·

CVE-2016-5425

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Tomcat on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions (affected versions not specified)
Description The issue is related to weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain root privileges by leveraging membership in the tomcat group.
Recommendations For Apache Tomcat on affected Linux distributions, consider restricting access to the tomcat group or modifying the permissions of /usr/lib/tmpfiles.d/tomcat.conf to prevent local users from gaining root privileges. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CESA-2016_2046
CVE-2016-5425
ELSA-2016-2046
MGASA-2016-0367
RHSA-2016:2046
RHSA-2016_2046

Affected Products

Apache Tomcat
Centos
Red Hat