Lucene search

K
cve[email protected]CVE-2017-5648
HistoryApr 17, 2017 - 4:59 p.m.

CVE-2017-5648

2017-04-1716:59:00
CWE-668
web.nvd.nist.gov
161
In Wild
4
cve
2017
5648
apache tomcat
application listeners
security manager
untrusted application

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

9.1 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

72.2%

While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use the appropriate facade object. When running an untrusted application under a SecurityManager, it was therefore possible for that untrusted application to retain a reference to the request or response object and thereby access and/or modify information associated with another web application.

Affected configurations

Vulners
NVD
Node
apachetomcatRange9.0.0.M19.0.0.M17
OR
apachetomcatRange8.5.08.5.11
OR
apachetomcatRange8.0.0.RC18.0.41
OR
apachetomcatRange7.0.07.0.75

CNA Affected

[
  {
    "product": "Apache Tomcat",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "status": "affected",
        "version": "9.0.0.M1 to 9.0.0.M17"
      },
      {
        "status": "affected",
        "version": "8.5.0 to 8.5.11"
      },
      {
        "status": "affected",
        "version": "8.0.0.RC1 to 8.0.41"
      },
      {
        "status": "affected",
        "version": "7.0.0 to 7.0.75"
      }
    ]
  }
]

References

Social References

More

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

9.1 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

72.2%