CVE-2016-0763

MEDIUM

Apache Tomcat <7.0.68, <8.0.31, <9.0.0.M3 - Privilege Escalation

Title source: llm

Description

The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLinkFactory.setGlobalContext callers are authorized, which allows remote authenticated users to bypass intended SecurityManager restrictions and read or write to arbitrary application data, or cause a denial of service (application disruption), via a web application that sets a crafted global context.

Scores

CVSS v3 6.3
EPSS 0.0029
EPSS Percentile 51.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Classification

CWE
CWE-264
Status draft

Affected Products (50)

debian/debian_linux
debian/debian_linux
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
... and 35 more

Timeline

Published Feb 25, 2016
Tracked Since Feb 18, 2026