PT-2016-6828 · Apache+2 · Apache Tomcat+4

Tomas Hoger

·

Published

2016-10-10

·

Updated

2023-02-12

·

CVE-2016-6325

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tomcat package on Red Hat Enterprise Linux (RHEL) versions 5 through 7 JBoss Web Server version 3.0 JBoss EWS version 2
Description The issue is related to weak permissions for certain configuration files, specifically (1) /etc/sysconfig/tomcat and (2) /etc/tomcat/tomcat.conf. This weakness allows local users to gain privileges by leveraging membership in the tomcat group.
Recommendations For Tomcat package on Red Hat Enterprise Linux (RHEL) versions 5 through 7, consider restricting access to the /etc/sysconfig/tomcat and /etc/tomcat/tomcat.conf files to prevent local users from gaining privileges. For JBoss Web Server version 3.0, restrict access to the /etc/sysconfig/tomcat and /etc/tomcat/tomcat.conf files to minimize the risk of exploitation. For JBoss EWS version 2, restrict access to the /etc/sysconfig/tomcat and /etc/tomcat/tomcat.conf files to prevent local users from gaining privileges.

Fix

Weakness Enumeration

Related Identifiers

CESA-2016_2045
CESA-2016_2046
CVE-2016-6325
MGASA-2016-0367
RHSA-2016:2045
RHSA-2016:2046
RHSA-2016_2045
RHSA-2016_2046
RHSA-2017:0455
RHSA-2017:0456

Affected Products

Centos
Jbossws
Jboss Web Server
Red Hat
Apache Tomcat