CVE-2016-5018
PoC —CVSS 3.1
9.1 critical
EPSS
10%p95
Published
()
Modified
Description
In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able to bypass a configured SecurityManager via a Tomcat utility method that was accessible to web applications.
- Vendors
- apachenetappcanonicaldebianredhatoracle
- Products
- tomcat, oncommand insight, oncommand shift, snap creator framework, ubuntu linux, debian linux, jboss enterprise application platform, jboss enterprise web server, enterprise linux desktop, enterprise linux eus, enterprise linux server, enterprise linux server aus
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.