← All CVEs

CVE-2016-0763

medium · 6.3

The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLinkFactory.setGlobalContext callers are authorized, which allows remote authenticated users to bypass intended SecurityManager restrictions and read or write to arbitrary application data, or cause a denial of service (application disruption), via a web application that sets a crafted global context.

6.3
CVSS
11.3%
EPSS (exploit prob.)
96th
EPSS percentile
2016-02-25
Published

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Weaknesses

CWE-264

Affected products

VendorProductAffected versions
debiandebian_linux7.0
debiandebian_linux8.0
apachetomcat7.0.0
apachetomcat7.0.2
apachetomcat7.0.4
apachetomcat7.0.5
apachetomcat7.0.6
apachetomcat7.0.10
apachetomcat7.0.11
apachetomcat7.0.12
apachetomcat7.0.14
apachetomcat7.0.16
apachetomcat7.0.19
apachetomcat7.0.20
apachetomcat7.0.21
apachetomcat7.0.22
apachetomcat7.0.23
apachetomcat7.0.25
apachetomcat7.0.26
apachetomcat7.0.27
apachetomcat7.0.28
apachetomcat7.0.29
apachetomcat7.0.30
apachetomcat7.0.32
apachetomcat7.0.33
apachetomcat7.0.34
apachetomcat7.0.35
apachetomcat7.0.37
apachetomcat7.0.39
apachetomcat7.0.40
apachetomcat7.0.41
apachetomcat7.0.42
apachetomcat7.0.47
apachetomcat7.0.50
apachetomcat7.0.52
apachetomcat7.0.53
apachetomcat7.0.54
apachetomcat7.0.55
apachetomcat7.0.56
apachetomcat7.0.57

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-0763