7.5

CVE-2016-6797

The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global JNDI resources to those resources explicitly linked to the web application. Therefore, it was possible for a web application to access any global JNDI resource whether an explicit ResourceLink had been configured or not.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Tomcat Version >= 6.0.0 <= 6.0.45
Apache ≫ Tomcat Version >= 7.0.0 <= 7.0.70
Apache ≫ Tomcat Version >= 8.0 <= 8.0.36
Apache ≫ Tomcat Version >= 8.5.0 <= 8.5.4
Apache ≫ Tomcat Version 9.0.0 Update milestone1
Apache ≫ Tomcat Version 9.0.0 Update milestone2
Apache ≫ Tomcat Version 9.0.0 Update milestone3
Apache ≫ Tomcat Version 9.0.0 Update milestone4
Apache ≫ Tomcat Version 9.0.0 Update milestone5
Apache ≫ Tomcat Version 9.0.0 Update milestone6
Apache ≫ Tomcat Version 9.0.0 Update milestone7
Apache ≫ Tomcat Version 9.0.0 Update milestone8
Apache ≫ Tomcat Version 9.0.0 Update milestone9
Oracle ≫ Tekelec Platform Distribution Version >= 7.4.0 <= 7.7.1
Debian ≫ Debian Linux Version 8.0
Netapp ≫ Oncommand Insight Version -
Netapp ≫ Oncommand Shift Version -
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Redhat ≫ Enterprise Linux Eus Version 7.4
Redhat ≫ Enterprise Linux Eus Version 7.5
Redhat ≫ Enterprise Linux Eus Version 7.6
Redhat ≫ Enterprise Linux Eus Version 7.7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.07% 0.941
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b%40%3Cdev.tomcat.apache.org%3E
https://www.oracle.com/security-alerts/cpuoct2021.html
Patch
Third Party Advisory
https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/88855876c33f2f9c532ffb75bfee570ccf0b17ffa77493745af9a17a%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc%40%3Cdev.tomcat.apache.org%3E
http://rhn.redhat.com/errata/RHSA-2017-0457.html
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:0455
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:0456
Third Party Advisory
https://usn.ubuntu.com/4557-1/
Third Party Advisory
http://www.debian.org/security/2016/dsa-3720
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2247
Third Party Advisory
https://security.netapp.com/advisory/ntap-20180605-0001/
Third Party Advisory
http://www.securityfocus.com/bid/93940
Broken Link
http://www.securitytracker.com/id/1037145
Broken Link
https://lists.apache.org/thread.html/9325837eb00cba5752c092047433c7f0415134d16e7f391447ff4352%40%3Cannounce.tomcat.apache.org%3E