CVE-2016-6325
13.10.2016, 14:59
The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 uses weak permissions for (1) /etc/sysconfig/tomcat and (2) /etc/tomcat/tomcat.conf, which allows local users to gain privileges by leveraging membership in the tomcat group.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apache | tomcat | - |
𝑥
= Vulnerable software versions
Ubuntu Releases
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| tomcat |
| ||
| tomcat-admin-webapps |
| ||
| tomcat-docs-webapp |
| ||
| tomcat-el-2.2-api |
| ||
| tomcat-javadoc |
| ||
| tomcat-jsp-2.2-api |
| ||
| tomcat-jsvc |
| ||
| tomcat-lib |
| ||
| tomcat-servlet-3.0-api |
| ||
| tomcat-webapps |
| ||
| tomcat6 |
| ||
| tomcat6-admin-webapps |
| ||
| tomcat6-docs-webapp |
| ||
| tomcat6-el-2.1-api |
| ||
| tomcat6-javadoc |
| ||
| tomcat6-jsp-2.1-api |
| ||
| tomcat6-lib |
| ||
| tomcat6-servlet-2.5-api |
| ||
| tomcat6-webapps |
|
Common Weakness Enumeration
References