CVE-2016-0763Improper Verification of Source of a Communication Channel in Apache Tomcat

Severity
6.3MEDIUMNVD
EPSS
0.3%
top 47.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 25
Latest updateMay 14

Description

The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLinkFactory.setGlobalContext callers are authorized, which allows remote authenticated users to bypass intended SecurityManager restrictions and read or write to arbitrary application data, or cause a denial of service (application disruption), via a web application that sets a crafted global context.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:LExploitability: 2.8 | Impact: 3.4

Affected Packages1 packages

NVDapache/tomcat65 versions+64

Also affects: Debian Linux 7.0, 8.0, Ubuntu Linux 12.04, 14.04, 15.10, 16.04

🔴Vulnerability Details

4
GHSA
Improper Verification of Source of a Communication Channel in Apache Tomcat2022-05-14
OSV
Improper Verification of Source of a Communication Channel in Apache Tomcat2022-05-14
CVEList
CVE-2016-0763: The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory2016-02-25
OSV
CVE-2016-0763: The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory2016-02-24

📋Vendor Advisories

4
Ubuntu
Tomcat vulnerabilities2016-07-05
Red Hat
tomcat: security manager bypass via setGlobalContext()2016-02-22
Debian
CVE-2016-0763: tomcat9 - The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.jav...2016
Apache
Apache tomcat: CVE-2016-0763

💬Community

4
Bugzilla
CVE-2015-5351 CVE-2016-0714 CVE-2016-0706 CVE-2015-5345 CVE-2015-5346 CVE-2016-0763 CVE-2016-3092 tomcat: multiple security vulnerabilities [epel-6]2016-07-01
Bugzilla
CVE-2016-0763 tomcat: security manager bypass via setGlobalContext()2016-02-23
Bugzilla
CVE-2015-5174 CVE-2015-5351 CVE-2016-0714 CVE-2016-0706 CVE-2015-5345 CVE-2015-5346 CVE-2016-0763 tomcat: multiple security vulnerabilities [epel-6]2016-02-23
Bugzilla
CVE-2015-5174 CVE-2015-5351 CVE-2016-0714 CVE-2016-0706 CVE-2015-5345 CVE-2015-5346 CVE-2016-0763 tomcat: multiple security vulnerabilities [fedora-all]2016-02-23
CVE-2016-0763 — Apache Tomcat vulnerability | cvebase