In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able to bypass a configured SecurityManager via a Tomcat utility method that was accessible to web applications.
2017-08-10T16:29:00.407
2025-04-20T01:37:25.860
Deferred
CVSSv3.1: 9.1 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:N
10.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | tomcat | ≤ 6.0.45 | Yes |
Application | apache | tomcat | ≤ 7.0.70 | Yes |
Application | apache | tomcat | ≤ 8.0.36 | Yes |
Application | apache | tomcat | ≤ 8.5.4 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | netapp | oncommand_insight | - | Yes |
Application | netapp | oncommand_shift | - | Yes |
Application | netapp | snap_creator_framework | - | Yes |
Operating System | canonical | ubuntu_linux | 16.04 | Yes |
Operating System | debian | debian_linux | 8.0 | Yes |
Application | redhat | jboss_enterprise_application_platform | 6.4 | Yes |
Application | redhat | jboss_enterprise_web_server | 3.0.0 | Yes |
Operating System | redhat | enterprise_linux_desktop | 7.0 | Yes |
Operating System | redhat | enterprise_linux_eus | 7.4 | Yes |
Operating System | redhat | enterprise_linux_eus | 7.5 | Yes |
Operating System | redhat | enterprise_linux_eus | 7.6 | Yes |
Operating System | redhat | enterprise_linux_eus | 7.7 | Yes |
Operating System | redhat | enterprise_linux_server | 7.0 | Yes |
Operating System | redhat | enterprise_linux_server_aus | 7.4 | Yes |
Operating System | redhat | enterprise_linux_server_aus | 7.6 | Yes |
Operating System | redhat | enterprise_linux_server_aus | 7.7 | Yes |
Operating System | redhat | enterprise_linux_server_tus | 7.6 | Yes |
Operating System | redhat | enterprise_linux_server_tus | 7.7 | Yes |
Operating System | redhat | enterprise_linux_workstation | 7.0 | Yes |
Application | oracle | tekelec_platform_distribution | ≤ 7.7.1 | Yes |