Vulnerability Database

296,138

Total vulnerabilities in the database

CVE-2014-7810

The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypass a SecurityManager protection mechanism via a web application that leverages use of incorrect privileges during EL evaluation.

CVSS v2:

  • Severity: Medium
  • Score: 5
  • AV:N/AC:L/Au:N/C:N/I:P/A:N
Software From Fixed in
debian / debian_linux 7.0 7.0.x
apache / tomcat 7.0.2-beta 7.0.2-beta.x
apache / tomcat 6.0.33 6.0.33.x
apache / tomcat 6.0.0-alpha 6.0.0-alpha.x
apache / tomcat 7.0.49 7.0.49.x
apache / tomcat 6.0.39 6.0.39.x
apache / tomcat 7.0.12 7.0.12.x
apache / tomcat 6.0.6 6.0.6.x
apache / tomcat 7.0.53 7.0.53.x
apache / tomcat 6.0.4-alpha 6.0.4-alpha.x
apache / tomcat 7.0.20 7.0.20.x
apache / tomcat 6.0.11 6.0.11.x
apache / tomcat 7.0.34 7.0.34.x
apache / tomcat 7.0.8 7.0.8.x
apache / tomcat 7.0.55 7.0.55.x
apache / tomcat 7.0.1 7.0.1.x
apache / tomcat 7.0.2 7.0.2.x
apache / tomcat 7.0.5 7.0.5.x
apache / tomcat 7.0.4-beta 7.0.4-beta.x
apache / tomcat 6.0.7 6.0.7.x
apache / tomcat 6.0.4 6.0.4.x
apache / tomcat 7.0.22 7.0.22.x
apache / tomcat 7.0.39 7.0.39.x
apache / tomcat 7.0.26 7.0.26.x
apache / tomcat 7.0.46 7.0.46.x
apache / tomcat 8.0.5 8.0.5.x
apache / tomcat 6.0.15 6.0.15.x
apache / tomcat 7.0.28 7.0.28.x
apache / tomcat 8.0.1 8.0.1.x
apache / tomcat 7.0.0 7.0.0.x
apache / tomcat 7.0.50 7.0.50.x
apache / tomcat 7.0.6 7.0.6.x
apache / tomcat 8.0.0-rc2 8.0.0-rc2.x
apache / tomcat 7.0.18 7.0.18.x
apache / tomcat 6.0.20 6.0.20.x
apache / tomcat 8.0.12 8.0.12.x
apache / tomcat 7.0.14 7.0.14.x
apache / tomcat 6.0.9-beta 6.0.9-beta.x
apache / tomcat 6.0.10 6.0.10.x
apache / tomcat 8.0.15 8.0.15.x
apache / tomcat 6.0.31 6.0.31.x
apache / tomcat 6.0.29 6.0.29.x
apache / tomcat 7.0.48 7.0.48.x
apache / tomcat 7.0.11 7.0.11.x
apache / tomcat 8.0.0-rc1 8.0.0-rc1.x
apache / tomcat 6.0.3 6.0.3.x
apache / tomcat 7.0.23 7.0.23.x
apache / tomcat 7.0.0-beta 7.0.0-beta.x
apache / tomcat 6.0.9 6.0.9.x
apache / tomcat 6.0.1-alpha 6.0.1-alpha.x
apache / tomcat 6.0.7-alpha 6.0.7-alpha.x
apache / tomcat 6.0.24 6.0.24.x
apache / tomcat 7.0.44 7.0.44.x
apache / tomcat 6.0.37 6.0.37.x
apache / tomcat 6.0.17 6.0.17.x
apache / tomcat 7.0.7 7.0.7.x
apache / tomcat 7.0.52 7.0.52.x
apache / tomcat 7.0.42 7.0.42.x
apache / tomcat 6.0.32 6.0.32.x
apache / tomcat 6.0.28 6.0.28.x
apache / tomcat 7.0.37 7.0.37.x
apache / tomcat 7.0.29 7.0.29.x
apache / tomcat 7.0.45 7.0.45.x
apache / tomcat 8.0.11 8.0.11.x
apache / tomcat 8.0.0-rc10 8.0.0-rc10.x
apache / tomcat 6.0.0 6.0.0.x
apache / tomcat 7.0.13 7.0.13.x
apache / tomcat 7.0.47 7.0.47.x
apache / tomcat 6.0.14 6.0.14.x
apache / tomcat 7.0.41 7.0.41.x
apache / tomcat 7.0.31 7.0.31.x
apache / tomcat 7.0.30 7.0.30.x
apache / tomcat 7.0.15 7.0.15.x
apache / tomcat 7.0.19 7.0.19.x
apache / tomcat 7.0.16 7.0.16.x
apache / tomcat 6.0.6-alpha 6.0.6-alpha.x
apache / tomcat 6.0.41 6.0.41.x
apache / tomcat 7.0.10 7.0.10.x
apache / tomcat 7.0.36 7.0.36.x
apache / tomcat 6.0.1 6.0.1.x
apache / tomcat 7.0.25 7.0.25.x
apache / tomcat 6.0.12 6.0.12.x
apache / tomcat 7.0.54 7.0.54.x
apache / tomcat 7.0.35 7.0.35.x
apache / tomcat 8.0.3 8.0.3.x
apache / tomcat 6.0.18 6.0.18.x
apache / tomcat 7.0.57 7.0.57.x
apache / tomcat 7.0.43 7.0.43.x
apache / tomcat 6.0.2-alpha 6.0.2-alpha.x
apache / tomcat 8.0.14 8.0.14.x
apache / tomcat 8.0.9 8.0.9.x
apache / tomcat 8.0.0-rc5 8.0.0-rc5.x
apache / tomcat 7.0.32 7.0.32.x
apache / tomcat 7.0.38 7.0.38.x
apache / tomcat 6.0.43 6.0.43.x
apache / tomcat 6.0.5 6.0.5.x
apache / tomcat 7.0.21 7.0.21.x
apache / tomcat 7.0.27 7.0.27.x
apache / tomcat 6.0.7-beta 6.0.7-beta.x
apache / tomcat 7.0.24 7.0.24.x
apache / tomcat 7.0.17 7.0.17.x
apache / tomcat 7.0.40 7.0.40.x
apache / tomcat 6.0.30 6.0.30.x
apache / tomcat 6.0.2 6.0.2.x
apache / tomcat 7.0.9 7.0.9.x
apache / tomcat 6.0.2-beta 6.0.2-beta.x
apache / tomcat 6.0.13 6.0.13.x
apache / tomcat 7.0.4 7.0.4.x
apache / tomcat 8.0.8 8.0.8.x
apache / tomcat 7.0.3 7.0.3.x
apache / tomcat 7.0.56 7.0.56.x
apache / tomcat 6.0.8-alpha 6.0.8-alpha.x
apache / tomcat 6.0.26 6.0.26.x
apache / tomcat 6.0.19 6.0.19.x
apache / tomcat 6.0.27 6.0.27.x
apache / tomcat 6.0.35 6.0.35.x
apache / tomcat 6.0.16 6.0.16.x
apache / tomcat 6.0.36 6.0.36.x
apache / tomcat 7.0.33 7.0.33.x
apache / tomcat 6.0.8 6.0.8.x
Maven icon org.apache.tomcat / tomcat 6.0.0 6.0.44
Maven icon org.apache.tomcat / tomcat 7.0.0 7.0.58
Maven icon org.apache.tomcat / tomcat 8.0.0 8.0.16