Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.807414
Kategorie:Web Servers
Titel:Apache Tomcat Security Manager Bypass Vulnerability (Feb 2016) - Linux
Zusammenfassung:Apache Tomcat is prone to a security manager bypass vulnerability.
Beschreibung:Summary:
Apache Tomcat is prone to a security manager bypass vulnerability.

Vulnerability Insight:
The flaw is due to an improper validation of
'ResourceLinkFactory.setGlobalContext()' method and is accessible by web
applications running under a security manager without any checks.

Vulnerability Impact:
Successful exploitation will allow remote
authenticated users to bypass intended SecurityManager restrictions and read
or write to arbitrary application data, or cause a denial of service.

Affected Software/OS:
Apache Tomcat 7.0.0 before 7.0.68,
8.0.0.RC1 before 8.0.31, and 9.0.0.M1 before 9.0.0.M2 on Linux.

Solution:
Upgrade to version 7.0.68 or
8.0.32 or 9.0.0.M3 or later.

CVSS Score:
6.5

CVSS Vector:
AV:N/AC:L/Au:S/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2016-0763
BugTraq ID: 83326
http://www.securityfocus.com/bid/83326
Bugtraq: 20160222 [SECURITY] CVE-2016-0763 Apache Tomcat Security Manager Bypass (Google Search)
http://seclists.org/bugtraq/2016/Feb/147
Debian Security Information: DSA-3530 (Google Search)
http://www.debian.org/security/2016/dsa-3530
Debian Security Information: DSA-3552 (Google Search)
http://www.debian.org/security/2016/dsa-3552
Debian Security Information: DSA-3609 (Google Search)
http://www.debian.org/security/2016/dsa-3609
http://lists.fedoraproject.org/pipermail/package-announce/2016-March/179356.html
https://security.gentoo.org/glsa/201705-09
https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551@%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c@%3Cdev.tomcat.apache.org%3E
RedHat Security Advisories: RHSA-2016:1087
https://access.redhat.com/errata/RHSA-2016:1087
RedHat Security Advisories: RHSA-2016:1088
https://access.redhat.com/errata/RHSA-2016:1088
RedHat Security Advisories: RHSA-2016:1089
http://rhn.redhat.com/errata/RHSA-2016-1089.html
RedHat Security Advisories: RHSA-2016:2599
http://rhn.redhat.com/errata/RHSA-2016-2599.html
RedHat Security Advisories: RHSA-2016:2807
http://rhn.redhat.com/errata/RHSA-2016-2807.html
RedHat Security Advisories: RHSA-2016:2808
http://rhn.redhat.com/errata/RHSA-2016-2808.html
http://www.securitytracker.com/id/1035069
SuSE Security Announcement: SUSE-SU-2016:0769 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00047.html
SuSE Security Announcement: SUSE-SU-2016:0822 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00069.html
SuSE Security Announcement: openSUSE-SU-2016:0865 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00085.html
http://www.ubuntu.com/usn/USN-3024-1
CopyrightCopyright (C) 2016 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.