CVE-2016-0706Sensitive Information Exposure in Apache Tomcat

Severity
4.3MEDIUMNVD
EPSS
1.5%
top 18.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 25
Latest updateMay 14

Description

Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 does not place org.apache.catalina.manager.StatusManagerServlet on the org/apache/catalina/core/RestrictedServlets.properties list, which allows remote authenticated users to bypass intended SecurityManager restrictions and read arbitrary HTTP requests, and consequently discover session ID values, via a crafted web application.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages1 packages

NVDapache/tomcat90 versions+89

Also affects: Debian Linux 7.0, 8.0, Ubuntu Linux 12.04, 14.04, 15.10, 16.04

🔴Vulnerability Details

4
OSV
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat2022-05-14
GHSA
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat2022-05-14
CVEList
CVE-2016-0706: Apache Tomcat 62016-02-25
OSV
CVE-2016-0706: Apache Tomcat 62016-02-24

📋Vendor Advisories

4
Ubuntu
Tomcat vulnerabilities2016-07-05
Red Hat
tomcat: security manager bypass via StatusManagerServlet2016-02-22
Debian
CVE-2016-0706: tomcat9 - Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x b...2016
Apache
Apache tomcat: CVE-2016-0706

💬Community

4
Bugzilla
CVE-2015-5351 CVE-2016-0714 CVE-2016-0706 CVE-2015-5345 CVE-2015-5346 CVE-2016-0763 CVE-2016-3092 tomcat: multiple security vulnerabilities [epel-6]2016-07-01
Bugzilla
CVE-2015-5174 CVE-2015-5351 CVE-2016-0714 CVE-2016-0706 CVE-2015-5345 CVE-2015-5346 CVE-2016-0763 tomcat: multiple security vulnerabilities [epel-6]2016-02-23
Bugzilla
CVE-2016-0706 tomcat: security manager bypass via StatusManagerServlet2016-02-23
Bugzilla
CVE-2015-5174 CVE-2015-5351 CVE-2016-0714 CVE-2016-0706 CVE-2015-5345 CVE-2015-5346 CVE-2016-0763 tomcat: multiple security vulnerabilities [fedora-all]2016-02-23
CVE-2016-0706 — Sensitive Information Exposure | cvebase