Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:10905
HistoryJan 15, 2019 - 8:53 a.m.

Privilege Escalation

2019-01-1508:53:56
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.0004 Low

EPSS

Percentile

5.1%

tomcat is vulnerable to privilege escalation. An error in the way the init script handled the tomcat5-initd.log, tomcat6-initd.log, tomcat7-initd.log and catalina.out log files allows a tomcat user to perform a symbolic link attack to change the ownership of an arbitrary system file to the tomcat user, allowing privilege escalation to root.