CVE-2017-5648

CRITICAL

Apache Tomcat < 9.0.0.M18 - Exposure to Wrong Actor

Title source: rule
STIX 2.1

Description

While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use the appropriate facade object. When running an untrusted application under a SecurityManager, it was therefore possible for that untrusted application to retain a reference to the request or response object and thereby access and/or modify information associated with another web application.

References (21)

Core 21
Core References
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201705-09
Vendor Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20180614-0001/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/97530
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:1801
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2017/dsa-3843
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1038220
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2017/dsa-3842
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:1809
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:1802
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2020/07/20/8

Scores

CVSS v3 9.1
EPSS 0.2176
EPSS Percentile 95.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-668
Status published
Products (50)
apache/tomcat 7.0.0
apache/tomcat 7.0.1
apache/tomcat 7.0.2
apache/tomcat 7.0.3
apache/tomcat 7.0.4
apache/tomcat 7.0.5
apache/tomcat 7.0.6
apache/tomcat 7.0.7
apache/tomcat 7.0.8
apache/tomcat 7.0.9
... and 40 more
Published Apr 17, 2017
Tracked Since Feb 18, 2026