Description
The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypass a SecurityManager protection mechanism via a web application that leverages use of incorrect privileges during EL evaluation.
CVSS vector
AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9Complexity: Low
Confidentiality: None
Availability: None
Affected Packages1 packages
Also affects: Debian Linux 7.0
🔴Vulnerability Details
4OSVImproper Access Control in Apache Tomcat↗2022-05-14 ▶ GHSAImproper Access Control in Apache Tomcat↗2022-05-14 ▶ CVEListCVE-2014-7810: The Expression Language (EL) implementation in Apache Tomcat 6↗2015-06-07 ▶ OSVCVE-2014-7810: The Expression Language (EL) implementation in Apache Tomcat 6↗2015-06-07 ▶ 📋Vendor Advisories
4UbuntuTomcat vulnerabilities↗2015-06-25 ▶ UbuntuTomcat vulnerabilities↗2015-06-25 ▶ Red HatTomcat/JbossWeb: security manager bypass via EL expressions↗2015-05-14 ▶ ApacheApache tomcat: CVE-2014-7810↗ ▶ 💬Community
3BugzillaCVE-2014-7810 tomcat: Tomcat/JbossWeb: security manager bypass via EL expressions [epel-6]↗2015-05-18 ▶ BugzillaCVE-2014-7810 Tomcat/JbossWeb: security manager bypass via EL expressions↗2015-05-18 ▶ BugzillaCVE-2014-7810 tomcat: Tomcat/JbossWeb: security manager bypass via EL expressions [fedora-all]↗2015-05-18 ▶