CVE-2016-0714Improper Access Control in Apache Tomcat

Severity
8.8HIGHNVD
EPSS
6.0%
top 9.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 25
Latest updateMay 14

Description

The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 mishandles session attributes, which allows remote authenticated users to bypass intended SecurityManager restrictions and execute arbitrary code in a privileged context via a web application that places a crafted object in a session.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

NVDapache/tomcat90 versions+89

Also affects: Debian Linux 7.0, 8.0, Ubuntu Linux 12.04, 14.04, 15.10, 16.04

🔴Vulnerability Details

4
GHSA
Improper Access Control in Apache Tomcat2022-05-14
OSV
Improper Access Control in Apache Tomcat2022-05-14
CVEList
CVE-2016-0714: The session-persistence implementation in Apache Tomcat 62016-02-25
OSV
CVE-2016-0714: The session-persistence implementation in Apache Tomcat 62016-02-24

📋Vendor Advisories

4
Ubuntu
Tomcat vulnerabilities2016-07-05
Red Hat
tomcat: Security Manager bypass via persistence mechanisms2016-02-22
Debian
CVE-2016-0714: tomcat9 - The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x b...2016
Apache
Apache tomcat: CVE-2016-0714

💬Community

4
Bugzilla
CVE-2015-5351 CVE-2016-0714 CVE-2016-0706 CVE-2015-5345 CVE-2015-5346 CVE-2016-0763 CVE-2016-3092 tomcat: multiple security vulnerabilities [epel-6]2016-07-01
Bugzilla
CVE-2016-0714 tomcat: Security Manager bypass via persistence mechanisms2016-02-23
Bugzilla
CVE-2015-5174 CVE-2015-5351 CVE-2016-0714 CVE-2016-0706 CVE-2015-5345 CVE-2015-5346 CVE-2016-0763 tomcat: multiple security vulnerabilities [epel-6]2016-02-23
Bugzilla
CVE-2015-5174 CVE-2015-5351 CVE-2016-0714 CVE-2016-0706 CVE-2015-5345 CVE-2015-5346 CVE-2016-0763 tomcat: multiple security vulnerabilities [fedora-all]2016-02-23
CVE-2016-0714 — Improper Access Control in Apache | cvebase