7.8

CVE-2016-6325

The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 uses weak permissions for (1) /etc/sysconfig/tomcat and (2) /etc/tomcat/tomcat.conf, which allows local users to gain privileges by leveraging membership in the tomcat group.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheTomcat Version-
   RedhatJboss Enterprise Web Server Version2.0.0
   RedhatJboss Web Server Version3.0
   RedhatEnterprise Linux Version5.0
   RedhatEnterprise Linux Version6.0
   RedhatEnterprise Linux Version7.0
   RedhatEnterprise Linux Desktop Version6.0
   RedhatEnterprise Linux Desktop Version7.0
   RedhatEnterprise Linux Hpc Node Version6.0
   RedhatEnterprise Linux Hpc Node Version7.0
   RedhatEnterprise Linux Hpc Node Eus Version7.2
   RedhatEnterprise Linux Server Version6.0
   RedhatEnterprise Linux Server Version7.0
   RedhatEnterprise Linux Server Aus Version7.2
   RedhatEnterprise Linux Server Eus Version7.2
   RedhatEnterprise Linux Workstation Version6.0
   RedhatEnterprise Linux Workstation Version7.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.1% 0.274
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C