CVE-2016-0706

Aliases:GHSA-6vx3-hr43-cfrh
Advisory lineage Upstream: 0 Downstream: 17
Modified
Published: 25 Feb 2016, 01:00
Last modified:05 Aug 2024, 22:30

Vulnerability Summary

Overall Risk (default)
low
17/100
CVSS Score
4.3 MEDIUM
v3.0 (nvd)
EPSS Score
1.43% LOW
1% probability +0.73%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

25 Feb 2016, 01:00
Published
Vulnerability first disclosed
05 Aug 2024, 22:30
Last Modified
Vulnerability information updated

Description

Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 does not place org.apache.catalina.manager.StatusManagerServlet on the org/apache/catalina/core/RestrictedServlets.properties list, which allows remote authenticated users to bypass intended SecurityManager restrictions and read arbitrary HTTP requests, and consequently discover session ID values, via a crafted web application.

CVSS Metrics

  • v3.0MEDIUMScore: 4.3CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
  • v2.0MEDIUMScore: 4AV:N/AC:L/Au:S/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 1.43% Percentile: 81%

Techniques & Countermeasures

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Affected Systems

  • UnknownTomcat

    6.0.0 | 6.0.0:alpha | 6.0.1 | 6.0.1:alpha | 6.0.2 | 6.0.2:alpha | 6.0.2:beta | 6.0.4 | 6.0.4:alpha | 6.0.10 | 6.0.11 | 6.0.13 | 6.0.14 | 6.0.16 | 6.0.18 | 6.0.20 | 6.0.24 | 6.0.26 | 6.0.28 | 6.0.29 | 6.0.30 | 6.0.32 | 6.0.33 | 6.0.35 | 6.0.36 | 6.0.37 | 6.0.39 | 6.0.41 | 6.0.43 | 6.0.44 | 7.0.0:beta | 7.0.2:beta | 7.0.4:beta | 7.0.5:beta | 7.0.6 | 7.0.10 | 7.0.11 | 7.0.12 | 7.0.14 | 7.0.16 | 7.0.19 | 7.0.20 | 7.0.21 | 7.0.22 | 7.0.23 | 7.0.25 | 7.0.26 | 7.0.27 | 7.0.28 | 7.0.29 | 7.0.30 | 7.0.32 | 7.0.33 | 7.0.34 | 7.0.35 | 7.0.37 | 7.0.39 | 7.0.40 | 7.0.41 | 7.0.42 | 7.0.47 | 7.0.50 | 7.0.52 | 7.0.53 | 7.0.54 | 7.0.55 | 7.0.56 | 7.0.57 | 7.0.59 | 7.0.61 | 7.0.62 | 7.0.63 | 7.0.64 | 7.0.65 | 7.0.67 | 8.0.0:rc1 | 8.0.0:rc10 | 8.0.0:rc3 | 8.0.0:rc5 | 8.0.1 | 8.0.3 | 8.0.11 | 8.0.12 | 8.0.14 | 8.0.15 | 8.0.17 | 8.0.18 | 8.0.20 | 8.0.21 | 8.0.22 | 8.0.23 | 8.0.24 | 8.0.26 | 8.0.27 | 8.0.28 | 8.0.29 | 8.0.30 | 9.0.0:milestone1

  • canonicalubuntu_linux

    12.04 | 14.04 | 15.10 | 16.04

  • debiandebian_linux

    7.0 | 8.0

  • org.apache.tomcattomcat

    ≥ 9.0.0.M1, < 9.0.0.M2 | ≥ 8.0.0.RC1, < 8.0.31 | ≥ 6.0.0, < 6.0.45

References (57)