Lucene search

K
redhatcveRedhat.comRH:CVE-2016-5425
HistoryOct 10, 2016 - 8:17 a.m.

CVE-2016-5425

2016-10-1008:17:29
redhat.com
access.redhat.com
27

0.001 Low

EPSS

Percentile

48.1%

It was discovered that the Tomcat packages installed configuration file /usr/lib/tmpfiles.d/tomcat.conf writeable to the tomcat group. A member of the group or a malicious web application deployed on Tomcat could use this flaw to escalate their privileges.