CVE-2016-6797
🟡 Monitoruj
Brak ograniczeń w dostępie do globalnych zasobów JNDI w Apache Tomcat pozwala na nieautoryzowany dostęp.
CVSS
7.5
EPSS
8.1%
Exploit
none
Vendor
apache
Opis źródłowy (NVD)
The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global JNDI resources to those resources explicitly linked to the web application. Therefore, it was possible for a web application to access any global JNDI resource whether an explicit ResourceLink had been configured or not.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 8.1% |
| Opublikowano (NVD) | 2017-08-10 22:29:00 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 22:16:39 UTC |
Referencje
- http://rhn.redhat.com/errata/RHSA-2017-0457.html ([email protected]) [Third Party Advisory]
- http://www.debian.org/security/2016/dsa-3720 ([email protected]) [Third Party Advisory]
- http://www.securityfocus.com/bid/93940 ([email protected]) [Broken Link]
- http://www.securitytracker.com/id/1037145 ([email protected]) [Broken Link]
- https://access.redhat.com/errata/RHSA-2017:0455 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2017:0456 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2017:2247 ([email protected]) [Third Party Advisory]
- https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3E ([email protected])
- https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113%40%3Cdev.tomcat.apache.org%3E ([email protected])
- https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3E ([email protected])
- https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b%40%3Cdev.tomcat.apache.org%3E ([email protected])
- https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3E ([email protected])
- https://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3%40%3Cdev.tomcat.apache.org%3E ([email protected])
- https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424%40%3Cdev.tomcat.apache.org%3E ([email protected])
- https://lists.apache.org/thread.html/88855876c33f2f9c532ffb75bfee570ccf0b17ffa77493745af9a17a%40%3Cdev.tomcat.apache.org%3E ([email protected])
- https://lists.apache.org/thread.html/9325837eb00cba5752c092047433c7f0415134d16e7f391447ff4352%40%3Cannounce.tomcat.apache.org%3E ([email protected])
- https://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc%40%3Cdev.tomcat.apache.org%3E ([email protected])
- https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95%40%3Cdev.tomcat.apache.org%3E ([email protected])
- https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb%40%3Cdev.tomcat.apache.org%3E ([email protected])
- https://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c%40%3Cdev.tomcat.apache.org%3E ([email protected])
- https://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b%40%3Cdev.tomcat.apache.org%3E ([email protected])
- https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E ([email protected])
- https://security.netapp.com/advisory/ntap-20180605-0001/ ([email protected]) [Third Party Advisory]
- https://usn.ubuntu.com/4557-1/ ([email protected]) [Third Party Advisory]
- https://www.oracle.com/security-alerts/cpuoct2021.html ([email protected]) [Patch, Third Party Advisory]