CVE Database
/

CVE-2016-6794

Back to search

CVE-2016-6794

Published: Aug 10, 2017

Modified: Sep 17, 2024

PUBLISHED

Description

When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, 6.0.0 to 6.0.45 the system property replacement feature for configuration files could be used by a malicious web application to bypass the SecurityManager and read system properties that should not be visible.

VendorProductVersions

Apache Software Foundation

Apache Tomcat

affected
9.0.0.M1 to 9.0.0.M9
affected
8.5.0 to 8.5.4
affected
8.0.0.RC1 to 8.0.36
affected
7.0.0 to 7.0.70
affected
6.0.0 to 6.0.45

References

RHSA-2017:2247
vendor-advisory
x_refsource_REDHAT
RHSA-2017:0457
vendor-advisory
x_refsource_REDHAT
RHSA-2017:0455
vendor-advisory
x_refsource_REDHAT
1037143
vdb-entry
x_refsource_SECTRACK
DSA-3720
vendor-advisory
x_refsource_DEBIAN
93943
vdb-entry
x_refsource_BID
RHSA-2017:0456
vendor-advisory
x_refsource_REDHAT
USN-4557-1
vendor-advisory
x_refsource_UBUNTU

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now