SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-6794

In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, 6.0.0 to 6.0.45 the system property replacement feature for configuration files could be used by a malicious web application to bypass the SecurityManager and…

MEDIUM 5.3EPSS 7.15%

Does this matter?

Lower severity and a low EPSS score (7.15%). Track it; it rarely justifies an emergency change on its own.

Description

When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, 6.0.0 to 6.0.45 the system property replacement feature for configuration files could be used by a malicious web application to bypass the SecurityManager and read system properties that should not be visible.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
7.15% probability · 94th percentile
CISA KEV
Not listed
Affected
apache/tomcat · debian/debian linux · redhat/jboss enterprise web server · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server tus · redhat/enterprise linux workstation · netapp/oncommand insight · netapp/oncommand shift · netapp/snap creator framework · canonical/ubuntu linux · oracle/tekelec platform distribution
Source
security@apache.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.