Back to search
CVE-2014-7810
Published: Jun 7, 2015
Modified: Aug 6, 2024
PUBLISHED
Description
The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypass a SecurityManager protection mechanism via a web application that leverages use of incorrect privileges during EL evaluation.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
RHSA-2016:0492
vendor-advisory
x_refsource_REDHAT
USN-2654-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2015:1622
vendor-advisory
x_refsource_REDHAT
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
x_refsource_CONFIRM
http://svn.apache.org/viewvc?view=revision&revision=1644018
x_refsource_CONFIRM
DSA-3530
vendor-advisory
x_refsource_DEBIAN
http://tomcat.apache.org/security-7.html
x_refsource_CONFIRM
http://svn.apache.org/viewvc?view=revision&revision=1645642
x_refsource_CONFIRM
HPSBUX03561
vendor-advisory
x_refsource_HP
RHSA-2016:2046
vendor-advisory
x_refsource_REDHAT
http://tomcat.apache.org/security-8.html
x_refsource_CONFIRM
DSA-3428
vendor-advisory
x_refsource_DEBIAN
http://tomcat.apache.org/security-6.html
x_refsource_CONFIRM
74665
vdb-entry
x_refsource_BID
1032330
vdb-entry
x_refsource_SECTRACK
USN-2655-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2015:1621
vendor-advisory
x_refsource_REDHAT
DSA-3447
vendor-advisory
x_refsource_DEBIAN
[tomcat-dev] 20190319 svn commit: r1855831 [23/30] - in /tomcat/site/trunk: ./ docs/ xdocs/
mailing-list
x_refsource_MLIST
[tomcat-dev] 20190325 svn commit: r1856174 [21/29] - in /tomcat/site/trunk: docs/ xdocs/ xdocs/stylesheets/
mailing-list
x_refsource_MLIST
[tomcat-dev] 20190413 svn commit: r1857494 [15/20] - in /tomcat/site/trunk: ./ docs/ xdocs/
mailing-list
x_refsource_MLIST
[tomcat-dev] 20190415 svn commit: r1857582 [16/22] - in /tomcat/site/trunk: docs/ xdocs/stylesheets/
mailing-list
x_refsource_MLIST
[tomcat-dev] 20200203 svn commit: r1873527 [23/30] - /tomcat/site/trunk/docs/
mailing-list
x_refsource_MLIST
[tomcat-dev] 20200213 svn commit: r1873980 [27/34] - /tomcat/site/trunk/docs/
mailing-list
x_refsource_MLIST
[tomcat-dev] 20200213 svn commit: r1873980 [26/34] - /tomcat/site/trunk/docs/
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now