5

CVE-2014-7810

The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypass a SecurityManager protection mechanism via a web application that leverages use of incorrect privileges during EL evaluation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DebianDebian Linux Version7.0
ApacheTomcat Version6.0.0
ApacheTomcat Version6.0.0 Updatealpha
ApacheTomcat Version6.0.1
ApacheTomcat Version6.0.1 Updatealpha
ApacheTomcat Version6.0.2
ApacheTomcat Version6.0.2 Updatealpha
ApacheTomcat Version6.0.2 Updatebeta
ApacheTomcat Version6.0.3
ApacheTomcat Version6.0.4
ApacheTomcat Version6.0.4 Updatealpha
ApacheTomcat Version6.0.5
ApacheTomcat Version6.0.6
ApacheTomcat Version6.0.6 Updatealpha
ApacheTomcat Version6.0.7
ApacheTomcat Version6.0.7 Updatealpha
ApacheTomcat Version6.0.7 Updatebeta
ApacheTomcat Version6.0.8
ApacheTomcat Version6.0.8 Updatealpha
ApacheTomcat Version6.0.9
ApacheTomcat Version6.0.9 Updatebeta
ApacheTomcat Version6.0.10
ApacheTomcat Version6.0.11
ApacheTomcat Version6.0.12
ApacheTomcat Version6.0.13
ApacheTomcat Version6.0.14
ApacheTomcat Version6.0.15
ApacheTomcat Version6.0.16
ApacheTomcat Version6.0.17
ApacheTomcat Version6.0.18
ApacheTomcat Version6.0.19
ApacheTomcat Version6.0.20
ApacheTomcat Version6.0.24
ApacheTomcat Version6.0.26
ApacheTomcat Version6.0.27
ApacheTomcat Version6.0.28
ApacheTomcat Version6.0.29
ApacheTomcat Version6.0.30
ApacheTomcat Version6.0.31
ApacheTomcat Version6.0.32
ApacheTomcat Version6.0.33
ApacheTomcat Version6.0.35
ApacheTomcat Version6.0.36
ApacheTomcat Version6.0.37
ApacheTomcat Version6.0.39
ApacheTomcat Version6.0.41
ApacheTomcat Version6.0.43
ApacheTomcat Version7.0.0
ApacheTomcat Version7.0.0 Updatebeta
ApacheTomcat Version7.0.1
ApacheTomcat Version7.0.2
ApacheTomcat Version7.0.2 Updatebeta
ApacheTomcat Version7.0.3
ApacheTomcat Version7.0.4
ApacheTomcat Version7.0.4 Updatebeta
ApacheTomcat Version7.0.5
ApacheTomcat Version7.0.6
ApacheTomcat Version7.0.7
ApacheTomcat Version7.0.8
ApacheTomcat Version7.0.9
ApacheTomcat Version7.0.10
ApacheTomcat Version7.0.11
ApacheTomcat Version7.0.12
ApacheTomcat Version7.0.13
ApacheTomcat Version7.0.14
ApacheTomcat Version7.0.15
ApacheTomcat Version7.0.16
ApacheTomcat Version7.0.17
ApacheTomcat Version7.0.18
ApacheTomcat Version7.0.19
ApacheTomcat Version7.0.20
ApacheTomcat Version7.0.21
ApacheTomcat Version7.0.22
ApacheTomcat Version7.0.23
ApacheTomcat Version7.0.24
ApacheTomcat Version7.0.25
ApacheTomcat Version7.0.26
ApacheTomcat Version7.0.27
ApacheTomcat Version7.0.28
ApacheTomcat Version7.0.29
ApacheTomcat Version7.0.30
ApacheTomcat Version7.0.31
ApacheTomcat Version7.0.32
ApacheTomcat Version7.0.33
ApacheTomcat Version7.0.34
ApacheTomcat Version7.0.35
ApacheTomcat Version7.0.36
ApacheTomcat Version7.0.37
ApacheTomcat Version7.0.38
ApacheTomcat Version7.0.39
ApacheTomcat Version7.0.40
ApacheTomcat Version7.0.41
ApacheTomcat Version7.0.42
ApacheTomcat Version7.0.43
ApacheTomcat Version7.0.44
ApacheTomcat Version7.0.45
ApacheTomcat Version7.0.46
ApacheTomcat Version7.0.47
ApacheTomcat Version7.0.48
ApacheTomcat Version7.0.49
ApacheTomcat Version7.0.50
ApacheTomcat Version7.0.52
ApacheTomcat Version7.0.53
ApacheTomcat Version7.0.54
ApacheTomcat Version7.0.55
ApacheTomcat Version7.0.56
ApacheTomcat Version7.0.57
ApacheTomcat Version8.0.0 Updaterc1
ApacheTomcat Version8.0.0 Updaterc10
ApacheTomcat Version8.0.0 Updaterc2
ApacheTomcat Version8.0.0 Updaterc5
ApacheTomcat Version8.0.1
ApacheTomcat Version8.0.3
ApacheTomcat Version8.0.5
ApacheTomcat Version8.0.8
ApacheTomcat Version8.0.9
ApacheTomcat Version8.0.11
ApacheTomcat Version8.0.12
ApacheTomcat Version8.0.14
ApacheTomcat Version8.0.15
ApacheTomcat Version6.0.0
   HpHp-ux Version11.31
ApacheTomcat Version6.0.0 Updatealpha
   HpHp-ux Version11.31
ApacheTomcat Version6.0.1
   HpHp-ux Version11.31
ApacheTomcat Version6.0.1 Updatealpha
   HpHp-ux Version11.31
ApacheTomcat Version6.0.2
   HpHp-ux Version11.31
ApacheTomcat Version6.0.2 Updatealpha
   HpHp-ux Version11.31
ApacheTomcat Version6.0.2 Updatebeta
   HpHp-ux Version11.31
ApacheTomcat Version6.0.3
   HpHp-ux Version11.31
ApacheTomcat Version6.0.4
   HpHp-ux Version11.31
ApacheTomcat Version6.0.4 Updatealpha
   HpHp-ux Version11.31
ApacheTomcat Version6.0.5
   HpHp-ux Version11.31
ApacheTomcat Version6.0.6
   HpHp-ux Version11.31
ApacheTomcat Version6.0.6 Updatealpha
   HpHp-ux Version11.31
ApacheTomcat Version6.0.7
   HpHp-ux Version11.31
ApacheTomcat Version6.0.7 Updatealpha
   HpHp-ux Version11.31
ApacheTomcat Version6.0.7 Updatebeta
   HpHp-ux Version11.31
ApacheTomcat Version6.0.8
   HpHp-ux Version11.31
ApacheTomcat Version6.0.8 Updatealpha
   HpHp-ux Version11.31
ApacheTomcat Version6.0.9
   HpHp-ux Version11.31
ApacheTomcat Version6.0.9 Updatebeta
   HpHp-ux Version11.31
ApacheTomcat Version6.0.10
   HpHp-ux Version11.31
ApacheTomcat Version6.0.11
   HpHp-ux Version11.31
ApacheTomcat Version6.0.12
   HpHp-ux Version11.31
ApacheTomcat Version6.0.13
   HpHp-ux Version11.31
ApacheTomcat Version6.0.14
   HpHp-ux Version11.31
ApacheTomcat Version6.0.15
   HpHp-ux Version11.31
ApacheTomcat Version6.0.16
   HpHp-ux Version11.31
ApacheTomcat Version6.0.17
   HpHp-ux Version11.31
ApacheTomcat Version6.0.18
   HpHp-ux Version11.31
ApacheTomcat Version6.0.19
   HpHp-ux Version11.31
ApacheTomcat Version6.0.20
   HpHp-ux Version11.31
ApacheTomcat Version6.0.24
   HpHp-ux Version11.31
ApacheTomcat Version6.0.26
   HpHp-ux Version11.31
ApacheTomcat Version6.0.27
   HpHp-ux Version11.31
ApacheTomcat Version6.0.28
   HpHp-ux Version11.31
ApacheTomcat Version6.0.29
   HpHp-ux Version11.31
ApacheTomcat Version6.0.30
   HpHp-ux Version11.31
ApacheTomcat Version6.0.31
   HpHp-ux Version11.31
ApacheTomcat Version6.0.32
   HpHp-ux Version11.31
ApacheTomcat Version6.0.33
   HpHp-ux Version11.31
ApacheTomcat Version6.0.35
   HpHp-ux Version11.31
ApacheTomcat Version6.0.36
   HpHp-ux Version11.31
ApacheTomcat Version6.0.37
   HpHp-ux Version11.31
ApacheTomcat Version6.0.39
   HpHp-ux Version11.31
ApacheTomcat Version6.0.41
   HpHp-ux Version11.31
ApacheTomcat Version6.0.43
   HpHp-ux Version11.31
ApacheTomcat Version7.0.0
   HpHp-ux Version11.31
ApacheTomcat Version7.0.0 Updatebeta
   HpHp-ux Version11.31
ApacheTomcat Version7.0.1
   HpHp-ux Version11.31
ApacheTomcat Version7.0.2
   HpHp-ux Version11.31
ApacheTomcat Version7.0.2 Updatebeta
   HpHp-ux Version11.31
ApacheTomcat Version7.0.3
   HpHp-ux Version11.31
ApacheTomcat Version7.0.4
   HpHp-ux Version11.31
ApacheTomcat Version7.0.4 Updatebeta
   HpHp-ux Version11.31
ApacheTomcat Version7.0.5
   HpHp-ux Version11.31
ApacheTomcat Version7.0.6
   HpHp-ux Version11.31
ApacheTomcat Version7.0.7
   HpHp-ux Version11.31
ApacheTomcat Version7.0.8
   HpHp-ux Version11.31
ApacheTomcat Version7.0.9
   HpHp-ux Version11.31
ApacheTomcat Version7.0.10
   HpHp-ux Version11.31
ApacheTomcat Version7.0.11
   HpHp-ux Version11.31
ApacheTomcat Version7.0.12
   HpHp-ux Version11.31
ApacheTomcat Version7.0.13
   HpHp-ux Version11.31
ApacheTomcat Version7.0.14
   HpHp-ux Version11.31
ApacheTomcat Version7.0.15
   HpHp-ux Version11.31
ApacheTomcat Version7.0.16
   HpHp-ux Version11.31
ApacheTomcat Version7.0.17
   HpHp-ux Version11.31
ApacheTomcat Version7.0.18
   HpHp-ux Version11.31
ApacheTomcat Version7.0.19
   HpHp-ux Version11.31
ApacheTomcat Version7.0.20
   HpHp-ux Version11.31
ApacheTomcat Version7.0.21
   HpHp-ux Version11.31
ApacheTomcat Version7.0.22
   HpHp-ux Version11.31
ApacheTomcat Version7.0.23
   HpHp-ux Version11.31
ApacheTomcat Version7.0.24
   HpHp-ux Version11.31
ApacheTomcat Version7.0.25
   HpHp-ux Version11.31
ApacheTomcat Version7.0.26
   HpHp-ux Version11.31
ApacheTomcat Version7.0.27
   HpHp-ux Version11.31
ApacheTomcat Version7.0.28
   HpHp-ux Version11.31
ApacheTomcat Version7.0.29
   HpHp-ux Version11.31
ApacheTomcat Version7.0.30
   HpHp-ux Version11.31
ApacheTomcat Version7.0.31
   HpHp-ux Version11.31
ApacheTomcat Version7.0.32
   HpHp-ux Version11.31
ApacheTomcat Version7.0.33
   HpHp-ux Version11.31
ApacheTomcat Version7.0.34
   HpHp-ux Version11.31
ApacheTomcat Version7.0.35
   HpHp-ux Version11.31
ApacheTomcat Version7.0.36
   HpHp-ux Version11.31
ApacheTomcat Version7.0.37
   HpHp-ux Version11.31
ApacheTomcat Version7.0.38
   HpHp-ux Version11.31
ApacheTomcat Version7.0.39
   HpHp-ux Version11.31
ApacheTomcat Version7.0.40
   HpHp-ux Version11.31
ApacheTomcat Version7.0.41
   HpHp-ux Version11.31
ApacheTomcat Version7.0.42
   HpHp-ux Version11.31
ApacheTomcat Version7.0.43
   HpHp-ux Version11.31
ApacheTomcat Version7.0.44
   HpHp-ux Version11.31
ApacheTomcat Version7.0.45
   HpHp-ux Version11.31
ApacheTomcat Version7.0.46
   HpHp-ux Version11.31
ApacheTomcat Version7.0.47
   HpHp-ux Version11.31
ApacheTomcat Version7.0.48
   HpHp-ux Version11.31
ApacheTomcat Version7.0.49
   HpHp-ux Version11.31
ApacheTomcat Version7.0.50
   HpHp-ux Version11.31
ApacheTomcat Version7.0.52
   HpHp-ux Version11.31
ApacheTomcat Version7.0.53
   HpHp-ux Version11.31
ApacheTomcat Version7.0.54
   HpHp-ux Version11.31
ApacheTomcat Version7.0.55
   HpHp-ux Version11.31
ApacheTomcat Version7.0.56
   HpHp-ux Version11.31
ApacheTomcat Version7.0.57
   HpHp-ux Version11.31
ApacheTomcat Version8.0.0 Updaterc1
   HpHp-ux Version11.31
ApacheTomcat Version8.0.0 Updaterc10
   HpHp-ux Version11.31
ApacheTomcat Version8.0.0 Updaterc2
   HpHp-ux Version11.31
ApacheTomcat Version8.0.0 Updaterc5
   HpHp-ux Version11.31
ApacheTomcat Version8.0.1
   HpHp-ux Version11.31
ApacheTomcat Version8.0.3
   HpHp-ux Version11.31
ApacheTomcat Version8.0.5
   HpHp-ux Version11.31
ApacheTomcat Version8.0.8
   HpHp-ux Version11.31
ApacheTomcat Version8.0.9
   HpHp-ux Version11.31
ApacheTomcat Version8.0.11
   HpHp-ux Version11.31
ApacheTomcat Version8.0.12
   HpHp-ux Version11.31
ApacheTomcat Version8.0.14
   HpHp-ux Version11.31
ApacheTomcat Version8.0.15
   HpHp-ux Version11.31
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 12.05% 0.935
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.