← All CVEs

CVE-2016-5018

critical · 9.1

In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able to bypass a configured SecurityManager via a Tomcat utility method that was accessible to web applications.

9.1
CVSS
10.3%
EPSS (exploit prob.)
95th
EPSS percentile
2017-08-10
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected products

VendorProductAffected versions
apachetomcat>= 6.0.0, <= 6.0.45
apachetomcat>= 7.0.0, <= 7.0.70
apachetomcat>= 8.0, <= 8.0.36
apachetomcat>= 8.5.0, <= 8.5.4
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
netapponcommand_insightall versions
netapponcommand_shiftall versions
netappsnap_creator_frameworkall versions
canonicalubuntu_linux16.04
debiandebian_linux8.0
redhatjboss_enterprise_application_platform6.4
redhatjboss_enterprise_web_server3.0.0
redhatenterprise_linux_desktop7.0
redhatenterprise_linux_eus7.4
redhatenterprise_linux_eus7.5
redhatenterprise_linux_eus7.6
redhatenterprise_linux_eus7.7
redhatenterprise_linux_server7.0
redhatenterprise_linux_server_aus7.4
redhatenterprise_linux_server_aus7.6
redhatenterprise_linux_server_aus7.7
redhatenterprise_linux_server_tus7.6
redhatenterprise_linux_server_tus7.7
redhatenterprise_linux_workstation7.0
oracletekelec_platform_distribution>= 7.4.0, <= 7.7.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-5018