Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:11991
HistoryJan 15, 2019 - 9:10 a.m.

SecurityManager Bypass

2019-01-1509:10:45
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.003 Low

EPSS

Percentile

69.3%

Apache Tomcat Jasper 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 allows the bypass a SecurityManager protection mechanism by using a web application that uses the incorrect privileges during an EL evaluation. This is caused because it does not take into account the possibility of an accessible interface implemented by an inaccessible class.

References