cbcvebase.
CVE-2016-5018
published 2017-08-10

CVE-2016-5018: In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able to bypass…

PriorityP266critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EXPLOIT
EPSS
10.30%
95.2th percentile
In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able to bypass a configured SecurityManager via a Tomcat utility method that was accessible to web applications.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
apachetomcat
apachetomcat
apachetomcat6.0.0 – 6.0.45
apachetomcat7.0.0 – 7.0.70
apachetomcat8.0 – 8.0.36
apachetomcat8.5.0 – 8.5.4
apache_software_foundationapache_tomcat
apache_software_foundationapache_tomcat
apache_software_foundationapache_tomcat
apache_software_foundationapache_tomcat
apache_software_foundationapache_tomcat
canonicalubuntu_linux
debiandebian_linux
oracletekelec_platform_distribution7.4.0 – 7.7.1
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_tus
redhatenterprise_linux_server_tus

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is exploited via the Tomcat `proprietaryEvaluate` / `IntrospectHelper` utility method accessible to web applications, allowing SecurityManager bypass. Monitor for web application calls to these internal Tomcat utility methods.
  • The exploit is specifically titled around `proprietaryEvaluate` and `introspecthelper` — audit web application code and deployed WARs for references to these Tomcat-internal methods as indicators of attempted sandbox escape.
  • Affected versions span a wide range; flag any Tomcat instance running 9.0.0.M1–9.0.0.M9, 8.5.0–8.5.4, 8.0.0.RC1–8.0.36, 7.0.0–7.0.70, or 6.0.0–6.0.45 as vulnerable to this SecurityManager bypass.
  • ·The fix was applied in two separate revision sets for 8.x; ensure both patch revisions (1754900/1760305 for 8.5.x and 1754901/1760307 for 8.0.x) are present, as a single patch set alone may be insufficient.

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv9.1CRITICAL
vendor_apache9.1CRITICAL
vendor_redhat9.1CRITICAL
vendor_ubuntu5.9MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.