Incorrect authorization in Apache Tomcat - CVE-2016-6797

 

Incorrect authorization in Apache Tomcat - CVE-2016-6797

Published: June 22, 2022


Vulnerability identifier: #VU64585
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-6797
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to ResourceLinkFactory implementation in Apache Tomcat does not limit web application access to global JNDI resources to those resources explicitly linked to the web application. A remote unauthenticated attacker can access any global JNDI resource whether an explicit ResourceLink had been configured or not.


Affected software

Apache Tomcat
Ubuntu
libservlet2.5-java (Ubuntu package)
EMC Cloud Tiering Appliance

How to mitigate CVE-2016-6797

Install updates from vendor's website.

Apache Tomcat - addressed in versions 6.0.46, 7.0.71, 8.0.37, 8.5.5, 9.0.0-M10
libservlet2.5-java (Ubuntu package) - update to 6.0.45+dfsg-1ubuntu0.1
EMC Cloud Tiering Appliance - addressed in versions 13.0.0.2.29, 13.1.0.2.20

External References

Related Security Bulletins