CVE-2016-5018

Published: 28 October 2016

In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able to bypass a configured SecurityManager via a Tomcat utility method that was accessible to web applications.

Priority

Medium

CVSS 3 base score: 7.5

Status

Package Release Status
tomcat6
Launchpad, Ubuntu, Debian
Upstream
Released (6.0.41-3)
Ubuntu 20.10 (Groovy Gorilla) Does not exist

Ubuntu 20.04 LTS (Focal Fossa) Does not exist

Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 LTS (Xenial Xerus) Not vulnerable
(6.0.45+dfsg-1)
Ubuntu 14.04 ESM (Trusty Tahr) Needed

Patches:
Upstream: https://svn.apache.org/viewvc?view=revision&revision=1754904
Upstream: https://svn.apache.org/viewvc?view=revision&revision=1761718
tomcat7
Launchpad, Ubuntu, Debian
Upstream
Released (7.0.72)
Ubuntu 20.10 (Groovy Gorilla) Does not exist

Ubuntu 20.04 LTS (Focal Fossa) Does not exist

Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable

Ubuntu 16.04 LTS (Xenial Xerus)
Released (7.0.68-1ubuntu0.3)
Ubuntu 14.04 ESM (Trusty Tahr)
Released (7.0.52-1ubuntu0.8)
Patches:
Upstream: https://svn.apache.org/viewvc?view=revision&revision=1754902
Upstream: https://svn.apache.org/viewvc?view=revision&revision=1760309
tomcat8
Launchpad, Ubuntu, Debian
Upstream
Released (8.0.37)
Ubuntu 20.10 (Groovy Gorilla) Does not exist

Ubuntu 20.04 LTS (Focal Fossa) Does not exist

Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(8.0.38-2)
Ubuntu 16.04 LTS (Xenial Xerus)
Released (8.0.32-1ubuntu1.3)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

Patches:
Upstream: https://svn.apache.org/viewvc?view=revision&revision=1754901
Upstream: https://svn.apache.org/viewvc?view=revision&revision=1760307