7.2

CVE-2004-1452

Tomcat before 5.0.27-r3 in Gentoo Linux sets the default permissions on the init scripts as tomcat:tomcat, but executes the scripts with root privileges, which could allow local users in the tomcat group to execute arbitrary commands as root by modifying the scripts.

Data is provided by the National Vulnerability Database (NVD)
GentooLinux Version0.5
GentooLinux Version0.7
GentooLinux Version1.1a
GentooLinux Version1.2
GentooLinux Version1.4
GentooLinux Version1.4 Updaterc1
GentooLinux Version1.4 Updaterc2
GentooLinux Version1.4 Updaterc3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.113
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C