PT-2016-7113 · Apache+5 · Apache Tomcat+5
Published
2016-09-05
·
Updated
2023-12-08
·
CVE-2016-6794
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Tomcat versions 9.0.0.M1 through 9.0.0.M9
Apache Tomcat versions 8.5.0 through 8.5.4
Apache Tomcat versions 8.0.0.RC1 through 8.0.36
Apache Tomcat versions 7.0.0 through 7.0.70
Apache Tomcat versions 6.0.0 through 6.0.45
Description
When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. However, the system property replacement feature for configuration files could be used by a malicious web application to bypass the SecurityManager and read system properties that should not be visible.
Recommendations
For Apache Tomcat versions 9.0.0.M1 through 9.0.0.M9, update to a version that includes a fix for this issue.
For Apache Tomcat versions 8.5.0 through 8.5.4, update to a version that includes a fix for this issue.
For Apache Tomcat versions 8.0.0.RC1 through 8.0.36, update to a version that includes a fix for this issue.
For Apache Tomcat versions 7.0.0 through 7.0.70, update to a version that includes a fix for this issue.
For Apache Tomcat versions 6.0.0 through 6.0.45, update to a version that includes a fix for this issue.
As a temporary workaround, consider disabling the system property replacement feature for configuration files until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Apache Tomcat
Centos
Red Hat
Suse
Ubuntu