CVE-2016-6797

HIGH

Apache Tomcat 6.0.0-6.0.45, 7.0.0-7.0.70, 8.0.0.RC1-8.0.36, 8.5.0-8.5.4, 9.0.0.M1-9.0.0.M9 - Incorrect Authorization

Title source: llm
STIX 2.1

Description

The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global JNDI resources to those resources explicitly linked to the web application. Therefore, it was possible for a web application to access any global JNDI resource whether an explicit ResourceLink had been configured or not.

References (25)

Core 25
Core References
Broken Link vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/93940
Broken Link vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1037145
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:2247
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2017-0457.html
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:0455
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2016/dsa-3720
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:0456
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4557-1/
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20180605-0001/
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuoct2021.html

Scores

CVSS v3 7.5
EPSS 0.0034
EPSS Percentile 56.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-863
Status published
Products (27)
apache/tomcat 9.0.0 milestone1 (9 CPE variants)
apache/tomcat 6.0.0 - 6.0.45
Apache Software Foundation/Apache Tomcat 6.0.0 to 6.0.45
Apache Software Foundation/Apache Tomcat 7.0.0 to 7.0.70
Apache Software Foundation/Apache Tomcat 8.0.0.RC1 to 8.0.36
Apache Software Foundation/Apache Tomcat 8.5.0 to 8.5.4
Apache Software Foundation/Apache Tomcat 9.0.0.M1 to 9.0.0.M9
canonical/ubuntu_linux 16.04
debian/debian_linux 8.0
netapp/oncommand_insight
... and 17 more
Published Aug 10, 2017
Tracked Since Feb 18, 2026