Privilege escalation in Apache Foundation products - CVE-2016-0714
Published: August 5, 2016 / Updated: January 11, 2017
Vulnerability details
The vulnerability allows a local attacker to bypass security manager restriction.
A local attacker, who controls web application, can abuse functionality of StandardManager and PersistentManager to gain control over sessions persistence, stored in files, in database or in custom Sore. Since session persistence is performed by Tomcat code with the permissions assigned to Tomcat internal code, the attacker can place specially crafted object into a session and execute arbitrary code on vulnerable system with elevated privileges.
Successful exploitation of the vulnerability may allow a local attacker to gain elevated privileges on the system.
Affected software
Apache Tomcat
Oracle Transportation Management
FlashSystem 840 9840-AE1 & 9843-AE1
Storage Copy Data Management
Oracle Linux
Oracle Solaris
Amazon Linux AMI
Fedora
SUSE Linux
FlashSystem 900 9840-AE2 and 9843-AE2
SAN Volume Controller and Storwize Family
tomcat
How to mitigate CVE-2016-0714
FlashSystem 900 9840-AE2 and 9843-AE2 - addressed in versions 1.3.0.6, 1.4.3.0
Storage Copy Data Management - update to 2.2.26.0
tomcat - addressed in versions 7.0.68-1.fc22, 7.0.68-2.fc22, 7.0.68-3.fc22, 7.0.70-2.el6, 8.0.32-3.fc23
SAN Volume Controller and Storwize Family - addressed in versions 7.5.0.8, 7.6.1.3
External References
- https://tomcat.apache.org/security-6.html#Fixed_in_Apache_Tomcat_6.0.45
- https://tomcat.apache.org/security-7.html
- https://tomcat.apache.org/security-8.html
- https://tomcat.apache.org/security-9.html
- http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.html
Related Security Bulletins
- Multiple vulnerabilities in Apache Tomcat
- SUSE Linux update for tomcat6
- Amazon Linux AMI update for tomcat6
- Multiple vulnerabilities in IBM FlashSystem models 840 and 900
- Multiple vulnerabilities in IBM SAN Volume Controller and Storwize Family
- Fedora 23 update for tomcat
- Fedora 22 update for tomcat
- Fedora 22 update for tomcat
- Fedora 22 update for tomcat
- Fedora EPEL 6 update for tomcat
- Multiple vulnerabilities in IBM Storage Copy Data Management