Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2016-5018

In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able to bypass a configured SecurityManager via a Tomcat utility method that was accessible to web applications.

CVSS v3:

  • Severity: Critical
  • Score: 9.1
  • AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CVSS v2:

  • Severity: Medium
  • Score: 6.4
  • AV:N/AC:L/Au:N/C:P/I:P/A:N

CWEs:

Software From Fixed in
apache / tomcat 6.0.0 6.0.45.x
apache / tomcat 7.0.0 7.0.70.x
apache / tomcat 8.0 8.0.36.x
apache / tomcat 8.5.0 8.5.4.x
canonical / ubuntu_linux 16.04 16.04.x
debian / debian_linux 8.0 8.0.x
redhat / enterprise_linux_desktop 7.0 7.0.x
redhat / enterprise_linux_workstation 7.0 7.0.x
redhat / jboss_enterprise_application_platform 6.4 6.4.x
redhat / enterprise_linux_server 7.0 7.0.x
redhat / enterprise_linux_server_aus 7.4 7.4.x
redhat / jboss_enterprise_web_server 3.0.0 3.0.0.x
redhat / enterprise_linux_eus 7.4 7.4.x
redhat / enterprise_linux_eus 7.5 7.5.x
redhat / enterprise_linux_server_tus 7.6 7.6.x
redhat / enterprise_linux_server_aus 7.6 7.6.x
redhat / enterprise_linux_eus 7.6 7.6.x
redhat / enterprise_linux_server_aus 7.7 7.7.x
redhat / enterprise_linux_server_tus 7.7 7.7.x
redhat / enterprise_linux_eus 7.7 7.7.x
oracle / tekelec_platform_distribution 7.4.0 7.7.1.x
org.apache.tomcat / tomcat-catalina 9.0.0.M1 9.0.0.M10
org.apache.tomcat / tomcat-catalina 8.5.0 8.5.5
org.apache.tomcat / tomcat-catalina 8.0.0RC1 8.0.37
org.apache.tomcat / tomcat-catalina 7.0.0 7.0.72
org.apache.tomcat / tomcat-catalina 6.0.0 6.0.47
apache / tomcat 9.0.0-milestone1 9.0.0-milestone1.x
apache / tomcat 9.0.0-milestone2 9.0.0-milestone2.x
apache / tomcat 9.0.0-milestone3 9.0.0-milestone3.x
apache / tomcat 9.0.0-milestone4 9.0.0-milestone4.x
apache / tomcat 9.0.0-milestone5 9.0.0-milestone5.x
apache / tomcat 9.0.0-milestone6 9.0.0-milestone6.x
apache / tomcat 9.0.0-milestone7 9.0.0-milestone7.x
apache / tomcat 9.0.0-milestone8 9.0.0-milestone8.x
apache / tomcat 9.0.0-milestone9 9.0.0-milestone9.x