CVE-2016-6794

MEDIUM

Apache Tomcat <9.0.0.M10, <8.5.5, <8.0.37, <7.0.71, <6.0.46 - Info ...

Title source: llm
STIX 2.1

Description

When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, 6.0.0 to 6.0.45 the system property replacement feature for configuration files could be used by a malicious web application to bypass the SecurityManager and read system properties that should not be visible.

References (25)

Core 25
Core References
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:2247
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2017-0457.html
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:0455
Broken Link vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1037143
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2016/dsa-3720
Broken Link vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/93943
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:0456
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4557-1/
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20180605-0001/
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuoct2021.html

Scores

CVSS v3 5.3
EPSS 0.0026
EPSS Percentile 49.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

Status published
Products (26)
apache/tomcat 9.0.0 milestone1 (9 CPE variants)
apache/tomcat 6.0.0 - 6.0.45
Apache Software Foundation/Apache Tomcat 6.0.0 to 6.0.45
Apache Software Foundation/Apache Tomcat 7.0.0 to 7.0.70
Apache Software Foundation/Apache Tomcat 8.0.0.RC1 to 8.0.36
Apache Software Foundation/Apache Tomcat 8.5.0 to 8.5.4
Apache Software Foundation/Apache Tomcat 9.0.0.M1 to 9.0.0.M9
canonical/ubuntu_linux 16.04
debian/debian_linux 8.0
netapp/oncommand_insight
... and 16 more
Published Aug 10, 2017
Tracked Since Feb 18, 2026