CVE-2016-8747
- EPSS 2.36%
- Veröffentlicht 14.03.2017 09:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.0.M15 in reverse-proxy configurations. Http11InputBuffer.java allows remote attackers to read data that was intended to be associated with a different...
CVE-2016-6325
- EPSS 0.1%
- Veröffentlicht 13.10.2016 14:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 uses weak permissions for (1) /etc/sysconfig/tomcat and (2) /etc/tomcat/tomcat.conf, which allows local users to gain privileges by leveraging me...
CVE-2016-5425
- EPSS 11.55%
- Veröffentlicht 13.10.2016 14:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain root privileges by leveraging me...
CVE-2016-1240
- EPSS 18.36%
- Veröffentlicht 03.10.2016 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debian jessie and the tomcat6 and libtomcat6-java packages before 6.0.35-1ubuntu3.8 on Ubuntu 12.04 LTS, the tomcat7 and libtomcat7-jav...
CVE-2016-5388
- EPSS 36.76%
- Veröffentlicht 19.07.2016 02:00:20
- Zuletzt bearbeitet 12.04.2025 10:46:40
Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, wh...
CVE-2016-3092
- EPSS 33.87%
- Veröffentlicht 04.07.2016 22:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (...
CVE-2016-0763
- EPSS 0.29%
- Veröffentlicht 25.02.2016 01:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLinkFactory.setGlobalContext callers are authorized, wh...
CVE-2016-0714
- EPSS 6.01%
- Veröffentlicht 25.02.2016 01:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 mishandles session attributes, which allows remote authenticated users to bypass intended SecurityManager restric...
CVE-2016-0706
- EPSS 1.54%
- Veröffentlicht 25.02.2016 01:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 does not place org.apache.catalina.manager.StatusManagerServlet on the org/apache/catalina/core/RestrictedServlets.properties list, which allows remote aut...
CVE-2015-5351
- EPSS 1.74%
- Veröffentlicht 25.02.2016 01:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions and send CSRF tokens for arbitrary new requests, which allows remote attackers to bypass a CSRF protec...