Security bypass in Apache Tomcat - CVE-2017-5664
Published: June 6, 2017 / Updated: June 12, 2017
Vulnerability identifier: #VU6950
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-5664
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass security restrictions on the target system.
The weakness exists due to improper handling of certain HTTP request methods for static error pages in Default Servlet. A remote attacker can bypass HTTP method restrictions and cause the error page to be deleted or replaced.
Successful exploitation of the vulnerability results in information modification.
The weakness exists due to improper handling of certain HTTP request methods for static error pages in Default Servlet. A remote attacker can bypass HTTP method restrictions and cause the error page to be deleted or replaced.
Successful exploitation of the vulnerability results in information modification.
Affected software
Apache Tomcat
Arch Linux
Amazon Linux AMI
Debian Linux
Red Hat Enterprise Linux for Scientific Computing
Fedora
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux EUS Compute Node
SUSE Linux
Opensuse
MySQL Enterprise Monitor
Percona Server for MySQL
Dell Support Assist Enterprise
Storage Copy Data Management
EMC Cloud Tiering Appliance
Oracle Communications Interactive Session Recorder
JBoss Enterprise Application Platform
tomcat
Arch Linux
Amazon Linux AMI
Debian Linux
Red Hat Enterprise Linux for Scientific Computing
Fedora
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux EUS Compute Node
SUSE Linux
Opensuse
MySQL Enterprise Monitor
Percona Server for MySQL
Dell Support Assist Enterprise
Storage Copy Data Management
EMC Cloud Tiering Appliance
Oracle Communications Interactive Session Recorder
JBoss Enterprise Application Platform
tomcat
How to mitigate CVE-2017-5664
Update to version 7.0.78, 8.0.44, 8.5.15, 9.0.0.M21.
Dell Support Assist Enterprise - update to 4.00.06.00
Storage Copy Data Management - update to 2.2.26.0
tomcat - addressed in versions 7.0.78-1.el6, 8.0.44-1.fc24, 8.0.44-1.fc25, 8.0.44-1.fc26
EMC Cloud Tiering Appliance - addressed in versions 13.0.0.2.29, 13.1.0.2.20
Storage Copy Data Management - update to 2.2.26.0
tomcat - addressed in versions 7.0.78-1.el6, 8.0.44-1.fc24, 8.0.44-1.fc25, 8.0.44-1.fc26
EMC Cloud Tiering Appliance - addressed in versions 13.0.0.2.29, 13.1.0.2.20
External References
Related Security Bulletins
- Security bypass in Apache Tomcat
- Arch Linux update for Apache Tomcat
- Arch Linux update for Apache Tomcat
- Debian update for tomcat7
- Debian update for tomcat8
- Multiple vulnerabilities in Oracle MySQL
- Amazon Linux AMI update for tomcat8
- Amazon Linux AMI update for tomcat7
- Amazon Linux AMI update for tomcat8
- openSUSE update for tomcat
- SUSE Linux update for tomcat
- SUSE Linux update for tomcat
- SUSE Linux update for tomcat
- Amazon Linux AMI update for tomcat7
- Multiple vulnerabilities in Percona Server for MySQL
- Red Hat update for tomcat6
- Red Hat update for jboss-ec2-eap
- Red Hat update for tomcat
- Multiple vulnerabilities in Dell EMC Cloud Tiering Appliance
- Multiple vulnerabilities in Dell Support Assist Enterprise
- Fedora 26 update for tomcat
- Fedora 25 update for tomcat
- Fedora 24 update for tomcat
- Fedora EPEL 6 update for tomcat
- Multiple vulnerabilities in IBM Storage Copy Data Management
- Multiple vulnerabilities in Oracle Communications Interactive Session Recorder