Security restrictions bypass in Apache Tomcat - CVE-2016-6796
Published: October 28, 2016 / Updated: June 26, 2017
Vulnerability identifier: #VU1092
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-6796
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows an application to bypass security manager restrictions on the target system.
The weakness improper access control. By modifying of configuration parameters for the JSP Servlet, a malicious application can bypass a configured SecurityManager.
Successful exploitation of the vulnerability results in security bypass.
The weakness improper access control. By modifying of configuration parameters for the JSP Servlet, a malicious application can bypass a configured SecurityManager.
Successful exploitation of the vulnerability results in security bypass.
Affected software
Apache Tomcat
FlashSystem 900 9840-AE2 and 9843-AE2
FlashSystem 840 9840-AE1 & 9843-AE1
EMC Cloud Tiering Appliance
Ubuntu
libservlet2.5-java (Ubuntu package)
jboss-ec2-eap (Red Hat package)
IBM Storwize V7000
IBM Storwize V5000
IBM Storwize V3700
IBM Storwize V3500
IBM FlashSystem V9000
IBM SAN Volume Controller
FlashSystem 900 9840-AE2 and 9843-AE2
FlashSystem 840 9840-AE1 & 9843-AE1
EMC Cloud Tiering Appliance
Ubuntu
libservlet2.5-java (Ubuntu package)
jboss-ec2-eap (Red Hat package)
IBM Storwize V7000
IBM Storwize V5000
IBM Storwize V3700
IBM Storwize V3500
IBM FlashSystem V9000
IBM SAN Volume Controller
How to mitigate CVE-2016-6796
Update to version 6.0.47, 7.0.72, 8.0.37, 8.5.5, 9.0.0.M10.
libservlet2.5-java (Ubuntu package) - update to 6.0.45+dfsg-1ubuntu0.1
jboss-ec2-eap (Red Hat package) - update to 7.5.16-1.Final_redhat_1.ep6.el6
IBM Storwize V7000 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V5000 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V3700 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V3500 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM FlashSystem V9000 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM SAN Volume Controller - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
EMC Cloud Tiering Appliance - addressed in versions 13.0.0.2.29, 13.1.0.2.20
jboss-ec2-eap (Red Hat package) - update to 7.5.16-1.Final_redhat_1.ep6.el6
IBM Storwize V7000 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V5000 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V3700 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V3500 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM FlashSystem V9000 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM SAN Volume Controller - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
EMC Cloud Tiering Appliance - addressed in versions 13.0.0.2.29, 13.1.0.2.20
External References
Related Security Bulletins
- Multiple vulnerabilities in Red Hat JBoss
- Multiple vulnerabilities in Dell EMC Cloud Tiering Appliance
- Multiple vulnerabilities in IBM FlashSystem models 840 and 900
- Multiple vulnerabilities in SAN Volume Controller, Storwize family and FlashSystem V9000 products
- Ubuntu update for tomcat6
- Red Hat JBoss Enterprise Application Platform 6 update for jboss-ec2-eap