ZeroHour

CVE-2016-6796

CVSS 3.1
7.5 high
EPSS
8%p95
Published
()
Modified
Description

A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via manipulation of the configuration parameters for the JSP Servlet.

Vendors
apachedebiannetappcanonicaloracleredhat
Products
tomcat, debian linux, oncommand insight, oncommand shift, snap creator framework, ubuntu linux, tekelec platform distribution, jboss enterprise application platform, jboss enterprise web server, enterprise linux desktop, enterprise linux eus, enterprise linux server
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.