ISOMAN

CVE

CVE-2016-0763

The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLinkFactory.setGlobalContext callers are authorized, which allows remote authenticated users to bypass intended SecurityManager restrictions and read or write to arbitrary application data, or cause a denial of service (application disruption), via a web application that sets a crafted global context.

Severity
MEDIUM
CVSS
6.3
Published
Modified

Linked Releases

References

  1. http://lists.fedoraproject.org/pipermail/package-announce/2016-March/179356.html
  2. http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00047.html
  3. http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00069.html
  4. http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00085.html
  5. http://rhn.redhat.com/errata/RHSA-2016-1089.html
  6. http://rhn.redhat.com/errata/RHSA-2016-2599.html
  7. http://rhn.redhat.com/errata/RHSA-2016-2807.html
  8. http://rhn.redhat.com/errata/RHSA-2016-2808.html
  9. http://seclists.org/bugtraq/2016/Feb/147
  10. http://svn.apache.org/viewvc?view=revision&revision=1725926
  11. http://svn.apache.org/viewvc?view=revision&revision=1725929
  12. http://svn.apache.org/viewvc?view=revision&revision=1725931
  13. http://tomcat.apache.org/security-7.html
  14. http://tomcat.apache.org/security-8.html
  15. http://tomcat.apache.org/security-9.html
  16. http://www.debian.org/security/2016/dsa-3530
  17. http://www.debian.org/security/2016/dsa-3552
  18. http://www.debian.org/security/2016/dsa-3609
  19. http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
  20. http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html