Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20287
HistoryMay 20, 2019 - 12:08 a.m.

Privilege Escalation

2019-05-2000:08:58
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.0004 Low

EPSS

Percentile

10.4%

Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 is vulnerable to privilege escalation attacks. Due to the setting of weak permissions in (1) /etc/sysconfig/tomcat and (2) /etc/tomcat/tomcat.conf, a member of the group or a malicious web application deployed on Tomcat is allowed to escalate their privileges.