CVE-2017-5648Resource Exposure in Software Foundation Apache Tomcat

CWE-668Resource Exposure13 documents9 sources
Severity
9.1CRITICALNVD
OSV7.5
EPSS
21.8%
top 4.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 17
Latest updateMay 13

Description

While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use the appropriate facade object. When running an untrusted application under a SecurityManager, it was therefore possible for that untrusted application to retain a reference to the request or response object and thereby access and/or modify information associated with another web application.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Affected Packages2 packages

NVDapache/tomcat131 versions+130

🔴Vulnerability Details

5
GHSA
Exposure of Resource to Wrong Sphere in Apache Tomcat2022-05-13
OSV
Exposure of Resource to Wrong Sphere in Apache Tomcat2022-05-13
OSV
tomcat7, tomcat8 vulnerabilities2018-01-08
CVEList
CVE-2017-5648: While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 92017-04-17
OSV
CVE-2017-5648: While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 92017-04-17

📋Vendor Advisories

4
Ubuntu
Tomcat vulnerabilities2018-01-08
Red Hat
tomcat: Calls to application listeners did not use the appropriate facade object2017-04-10
Debian
CVE-2017-5648: tomcat9 - While investigating bug 60718, it was noticed that some calls to application lis...2017
Apache
Apache tomcat: CVE-2017-5648

💬Community

3
Bugzilla
CVE-2017-5648 tomcat: Calls to application listeners did not use the appropriate facade object2017-04-11
Bugzilla
CVE-2017-5647 CVE-2017-5648 tomcat: various flaws [epel-6]2017-04-11
Bugzilla
CVE-2017-5647 CVE-2017-5648 tomcat: various flaws [fedora-all]2017-04-11