CVE-2017-5648
Published: 17 April 2017
While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use the appropriate facade object. When running an untrusted application under a SecurityManager, it was therefore possible for that untrusted application to retain a reference to the request or response object and thereby access and/or modify information associated with another web application.
Priority
Status
Package | Release | Status |
---|---|---|
tomcat6 Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
bionic |
Does not exist
|
|
cosmic |
Does not exist
|
|
disco |
Does not exist
|
|
eoan |
Does not exist
|
|
focal |
Does not exist
|
|
groovy |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
precise |
Not vulnerable
|
|
trusty |
Not vulnerable
|
|
upstream |
Not vulnerable
|
|
xenial |
Not vulnerable
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
tomcat7 Launchpad, Ubuntu, Debian |
artful |
Not vulnerable
(7.0.75-1)
|
bionic |
Not vulnerable
(7.0.75-1)
|
|
cosmic |
Not vulnerable
(7.0.75-1)
|
|
disco |
Does not exist
|
|
eoan |
Does not exist
|
|
focal |
Does not exist
|
|
groovy |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
precise |
Does not exist
(precise was needed)
|
|
trusty |
Released
(7.0.52-1ubuntu0.13)
|
|
upstream |
Released
(7.0.72-3)
|
|
xenial |
Needed
|
|
yakkety |
Ignored
(reached end-of-life)
|
|
zesty |
Not vulnerable
(7.0.75-1)
|
|
Patches: upstream: https://svn.apache.org/viewvc?view=revision&revision=1785777 |
||
tomcat8 Launchpad, Ubuntu, Debian |
artful |
Not vulnerable
(8.5.21-1ubuntu1)
|
bionic |
Not vulnerable
(8.5.21-1ubuntu1)
|
|
cosmic |
Not vulnerable
(8.5.21-1ubuntu1)
|
|
disco |
Does not exist
|
|
eoan |
Does not exist
|
|
focal |
Does not exist
|
|
groovy |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
precise |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Released
(8.5.11-2)
|
|
xenial |
Released
(8.0.32-1ubuntu1.5)
|
|
yakkety |
Ignored
(reached end-of-life)
|
|
zesty |
Released
(8.0.38-2ubuntu2.2)
|
|
Patches: upstream: https://svn.apache.org/viewvc?view=revision&revision=1785776 |
Severity score breakdown
Parameter | Value |
---|---|
Base score | 9.1 |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | High |
Availability impact | None |
Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |