Information disclosure in Apache Tomcat - CVE-2016-6797
Published: October 28, 2016 / Updated: October 31, 2016
Vulnerability identifier: #VU1091
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-6797
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows an application to gain access to global resources on the target system.
The weakness exists due to a flaw in the ResourceLinkFactory that allows a web application to obtain global JNDI resources.
Successful exploitation of the vulnerability results in application's access to global JNDI resources on the vulnerable system.
The weakness exists due to a flaw in the ResourceLinkFactory that allows a web application to obtain global JNDI resources.
Successful exploitation of the vulnerability results in application's access to global JNDI resources on the vulnerable system.
Affected software
Apache Tomcat
Ubuntu
Storage Copy Data Management
libservlet2.5-java (Ubuntu package)
How to mitigate CVE-2016-6797
Update to version 6.0.47, 7.0.72, 8.0.37, 8.5.5, 9.0.0.M10.
Storage Copy Data Management - update to 2.2.26.0
libservlet2.5-java (Ubuntu package) - update to 6.0.45+dfsg-1ubuntu0.1
libservlet2.5-java (Ubuntu package) - update to 6.0.45+dfsg-1ubuntu0.1