CVE-2016-6796
—CVSS 3.1
7.5 high
EPSS
8%p95
Published
()
Modified
Description
A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via manipulation of the configuration parameters for the JSP Servlet.
- Vendors
- apachedebiannetappcanonicaloracleredhat
- Products
- tomcat, debian linux, oncommand insight, oncommand shift, snap creator framework, ubuntu linux, tekelec platform distribution, jboss enterprise application platform, jboss enterprise web server, enterprise linux desktop, enterprise linux eus, enterprise linux server
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.