CVE-2016-5425
- EPSS 11.55%
- Veröffentlicht 13.10.2016 14:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain root privileges by leveraging me...
CVE-2016-1240
- EPSS 22.22%
- Veröffentlicht 03.10.2016 15:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debian jessie and the tomcat6 and libtomcat6-java packages before 6.0.35-1ubuntu3.8 on Ubuntu 12.04 LTS, the tomcat7 and libtomcat7-jav...
CVE-2016-5388
- EPSS 36.76%
- Veröffentlicht 19.07.2016 02:00:20
- Zuletzt bearbeitet 06.05.2026 22:30:45
Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, wh...
CVE-2016-3092
- EPSS 40.25%
- Veröffentlicht 04.07.2016 22:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (...
CVE-2016-0763
- EPSS 0.29%
- Veröffentlicht 25.02.2016 01:59:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLinkFactory.setGlobalContext callers are authorized, wh...
CVE-2016-0714
- EPSS 10.16%
- Veröffentlicht 25.02.2016 01:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 mishandles session attributes, which allows remote authenticated users to bypass intended SecurityManager restric...
CVE-2016-0706
- EPSS 1.54%
- Veröffentlicht 25.02.2016 01:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 does not place org.apache.catalina.manager.StatusManagerServlet on the org/apache/catalina/core/RestrictedServlets.properties list, which allows remote aut...
CVE-2015-5351
- EPSS 2.31%
- Veröffentlicht 25.02.2016 01:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions and send CSRF tokens for arbitrary new requests, which allows remote attackers to bypass a CSRF protec...
CVE-2015-5346
- EPSS 36.17%
- Veröffentlicht 25.02.2016 01:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to ...
CVE-2015-5345
- EPSS 49.88%
- Veröffentlicht 25.02.2016 01:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before considering security constraints and Filters, which allows remote attackers to determine the existence o...