Security Manager bypass in Apache Foundation products - CVE-2016-0706

 

Security Manager bypass in Apache Foundation products - CVE-2016-0706

Published: August 5, 2016 / Updated: January 11, 2017


Vulnerability identifier: #VU263
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-0706
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to obtain potentially sensitive information.

A local attacker, who controls web application, can use StatusManagerServlet, when a security manager was configured, to obtain potentially sensitive information, which belongs to other users. The attacker will be able to obtain a list of all deployed applications and a list of the HTTP request lines for all requests currently being processed. This could have exposed sensitive information from other web applications, such as session IDs, to the web application.

Successful exploitation of the vulnerability may allow a local attacker to gain access to potentially sensitive information.


Affected software

Virtual Desktop Infrastructure
Apache Tomcat
Oracle Transportation Management
FlashSystem 840 9840-AE1 & 9843-AE1
Storage Copy Data Management
Oracle Linux
Oracle Solaris
Amazon Linux AMI
Fedora
SUSE Linux
FlashSystem 900 9840-AE2 and 9843-AE2
SAN Volume Controller and Storwize Family
tomcat

How to mitigate CVE-2016-0706

Install the latest version Apache Tomcat 6.0.45, 7.0.68, 8.0.32 or 9.0.0.M3

FlashSystem 840 9840-AE1 & 9843-AE1 - addressed in versions 1.3.0.6, 1.4.3.0
FlashSystem 900 9840-AE2 and 9843-AE2 - addressed in versions 1.3.0.6, 1.4.3.0
Storage Copy Data Management - update to 2.2.26.0
tomcat - addressed in versions 7.0.68-1.fc22, 7.0.68-2.fc22, 7.0.68-3.fc22, 7.0.70-2.el6, 8.0.32-3.fc23
SAN Volume Controller and Storwize Family - addressed in versions 7.5.0.8, 7.6.1.3

External References

Related Security Bulletins