← All CVEs

CVE-2016-0714

high · 8.8

The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 mishandles session attributes, which allows remote authenticated users to bypass intended SecurityManager restrictions and execute arbitrary code in a privileged context via a web application that places a crafted object in a session.

8.8
CVSS
13.1%
EPSS (exploit prob.)
96th
EPSS percentile
2016-02-25
Published

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-264

Affected products

VendorProductAffected versions
apachetomcat6.0.0
apachetomcat6.0.0
apachetomcat6.0.1
apachetomcat6.0.1
apachetomcat6.0.2
apachetomcat6.0.2
apachetomcat6.0.2
apachetomcat6.0.4
apachetomcat6.0.4
apachetomcat6.0.10
apachetomcat6.0.11
apachetomcat6.0.13
apachetomcat6.0.14
apachetomcat6.0.16
apachetomcat6.0.18
apachetomcat6.0.20
apachetomcat6.0.24
apachetomcat6.0.26
apachetomcat6.0.28
apachetomcat6.0.29
apachetomcat6.0.30
apachetomcat6.0.32
apachetomcat6.0.33
apachetomcat6.0.35
apachetomcat6.0.36
apachetomcat6.0.37
apachetomcat6.0.39
apachetomcat6.0.41
apachetomcat6.0.43
apachetomcat6.0.44
apachetomcat7.0.0
apachetomcat7.0.2
apachetomcat7.0.4
apachetomcat7.0.5
apachetomcat7.0.6
apachetomcat7.0.10
apachetomcat7.0.11
apachetomcat7.0.12
apachetomcat7.0.14
apachetomcat7.0.16

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-0714