7.8

CVE-2016-5425

Exploit

The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain root privileges by leveraging membership in the tomcat group.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheTomcat Version-
   OracleInstantis Enterprisetrack Version17.1
   OracleInstantis Enterprisetrack Version17.2
   OracleInstantis Enterprisetrack Version17.3
   OracleLinux Version7 Update-
   RedhatEnterprise Linux Desktop Version7.0
   RedhatEnterprise Linux Server Version7.0
   RedhatEnterprise Linux Server Aus Version7.2
   RedhatEnterprise Linux Server Aus Version7.3
   RedhatEnterprise Linux Server Aus Version7.4
   RedhatEnterprise Linux Server Aus Version7.6
   RedhatEnterprise Linux Server Aus Version7.7
   RedhatEnterprise Linux Server Eus Version7.2
   RedhatEnterprise Linux Server Eus Version7.3
   RedhatEnterprise Linux Server Eus Version7.4
   RedhatEnterprise Linux Server Eus Version7.5
   RedhatEnterprise Linux Server Eus Version7.6
   RedhatEnterprise Linux Server Eus Version7.7
   RedhatEnterprise Linux Server Tus Version7.2
   RedhatEnterprise Linux Server Tus Version7.3
   RedhatEnterprise Linux Server Tus Version7.6
   RedhatEnterprise Linux Server Tus Version7.7
   RedhatEnterprise Linux Workstation Version7.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 14.47% 0.94
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.