7.8

CVE-2016-6325

The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 uses weak permissions for (1) /etc/sysconfig/tomcat and (2) /etc/tomcat/tomcat.conf, which allows local users to gain privileges by leveraging membership in the tomcat group.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Tomcat Version -
   Redhat ≫ Jboss Enterprise Web Server Version 2.0.0
   Redhat ≫ Jboss Web Server Version 3.0
   Redhat ≫ Enterprise Linux Version 5.0
   Redhat ≫ Enterprise Linux Version 6.0
   Redhat ≫ Enterprise Linux Version 7.0
   Redhat ≫ Enterprise Linux Desktop Version 6.0
   Redhat ≫ Enterprise Linux Desktop Version 7.0
   Redhat ≫ Enterprise Linux Hpc Node Version 6.0
   Redhat ≫ Enterprise Linux Hpc Node Version 7.0
   Redhat ≫ Enterprise Linux Hpc Node Eus Version 7.2
   Redhat ≫ Enterprise Linux Server Version 6.0
   Redhat ≫ Enterprise Linux Server Version 7.0
   Redhat ≫ Enterprise Linux Server Aus Version 7.2
   Redhat ≫ Enterprise Linux Server Eus Version 7.2
   Redhat ≫ Enterprise Linux Workstation Version 6.0
   Redhat ≫ Enterprise Linux Workstation Version 7.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.69% 0.48
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://rhn.redhat.com/errata/RHSA-2016-2046.html
Vendor Advisory
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.html
http://rhn.redhat.com/errata/RHSA-2016-2045.html
Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2017-0457.html
https://access.redhat.com/errata/RHSA-2017:0455
https://access.redhat.com/errata/RHSA-2017:0456
http://www.securityfocus.com/bid/93478
https://bugzilla.redhat.com/show_bug.cgi?id=1367447
Vendor Advisory
VDB Entry
Issue Tracking