ZeroHour

CVE-2016-5018

PoC
CVSS 3.1
9.1 critical
EPSS
10%p95
Published
()
Modified
Description

In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able to bypass a configured SecurityManager via a Tomcat utility method that was accessible to web applications.

Vendors
apachenetappcanonicaldebianredhatoracle
Products
tomcat, oncommand insight, oncommand shift, snap creator framework, ubuntu linux, debian linux, jboss enterprise application platform, jboss enterprise web server, enterprise linux desktop, enterprise linux eus, enterprise linux server, enterprise linux server aus
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.