CVE-2016-5018

Aliases:GHSA-4v3g-g84w-hv7r
Advisory lineage Upstream: 0 Downstream: 19
Modified
Published: 10 Aug 2017, 16:00
Last modified:16 Sept 2024, 18:38

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.1 CRITICAL
v3.1 (nvd)
EPSS Score
0.94% LOW
1% probability -0.03%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

10 Aug 2017, 16:00
Published
Vulnerability first disclosed
16 Sept 2024, 18:38
Last Modified
Vulnerability information updated

Description

In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able to bypass a configured SecurityManager via a Tomcat utility method that was accessible to web applications.

CVSS Metrics

  • v3.1CRITICALScore: 9.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • v2.0MEDIUMScore: 6.4AV:N/AC:L/Au:N/C:P/I:P/A:N

EPSS Trends

Current EPSS score: 0.94% Percentile: 77%

Affected Systems

  • apache software foundationapache tomcat

    9.0.0.M1 to 9.0.0.M9 | 8.5.0 to 8.5.4 | 8.0.0.RC1 to 8.0.36 | 7.0.0 to 7.0.70 | 6.0.0 to 6.0.45

  • UnknownTomcat

    ≥ 6.0.0, ≤ 6.0.45 | ≥ 7.0.0, ≤ 7.0.70 | ≥ 8.0, ≤ 8.0.36 | ≥ 8.5.0, ≤ 8.5.4 | 9.0.0:milestone1 | 9.0.0:milestone2 | 9.0.0:milestone3 | 9.0.0:milestone4 | 9.0.0:milestone5 | 9.0.0:milestone6 | 9.0.0:milestone7 | 9.0.0:milestone8 | 9.0.0:milestone9

  • canonicalubuntu_linux

    16.04

  • debiandebian_linux

    8.0

  • org.apache.tomcatjasper

    ≥ 6.0.0, < 6.0.47

  • org.apache.tomcattomcat-jasper

    ≥ 9.0.0.M1, < 9.0.0.M10 | ≥ 8.5.0, < 8.5.5 | ≥ 8.0.0RC1, < 8.0.37 | ≥ 7.0.0, < 7.0.72

  • org.apache.tomcat.embedtomcat-embed-jasper

    ≥ 9.0.0.M1, < 9.0.0.M10 | ≥ 8.5.0, < 8.5.5 | ≥ 8.0.0RC1, < 8.0.37 | ≥ 7.0.0, < 7.0.72 | ≥ 6.0.0, < 6.0.47

  • netapponcommand_insight

    na

  • netapponcommand_shift

    na

  • netappsnap_creator_framework

    na

  • oracletekelec_platform_distribution

    ≥ 7.4.0, ≤ 7.7.1

  • redhatenterprise_linux_desktop

    7.0

  • redhatenterprise_linux_eus

    7.4 | 7.5 | 7.6 | 7.7

  • redhatenterprise_linux_server

    7.0

  • redhatenterprise_linux_server_aus

    7.4 | 7.6 | 7.7

  • redhatenterprise_linux_server_tus

    7.6 | 7.7

  • redhatenterprise_linux_workstation

    7.0

  • redhatjboss_enterprise_application_platform

    6.4

  • redhatjboss_enterprise_web_server

    3.0.0

References (54)