CVE-2016-0763
MEDIUMApache Tomcat <7.0.68, <8.0.31, <9.0.0.M3 - Privilege Escalation
Title source: llmDescription
The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLinkFactory.setGlobalContext callers are authorized, which allows remote authenticated users to bypass intended SecurityManager restrictions and read or write to arbitrary application data, or cause a denial of service (application disruption), via a web application that sets a crafted global context.
References (33)
... and 13 more
Scores
CVSS v3
6.3
EPSS
0.0029
EPSS Percentile
51.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Classification
CWE
CWE-264
Status
draft
Affected Products (50)
debian/debian_linux
debian/debian_linux
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
... and 35 more
Timeline
Published
Feb 25, 2016
Tracked Since
Feb 18, 2026