CVE-2016-5018: Critical severity Apache Tomcat vulnerability
In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8. ...
Other sources
The following flaw was found in Tomcat:
A malicious web application was able to bypass a configured SecurityManager via a Tomcat utility method that was accessible to web applications.
Upstream patches:
6.0.47: https://svn.apache.org/viewvc?view=revision&revision=1754904 7.0.72: https://svn.apache.org/viewvc?view=revision&revision=1754902 8.5.5: https://svn.apache.org/viewvc?view=revision&revision=1754900 8.0.37: https://svn.apache.org/viewvc?view=revision&revision=1754901
External References:
https://tomcat.apache.org/security-6.html#FixedinApacheTomcat6.0.47 https://tomcat.apache.org/security-7.html#FixedinApacheTomcat7.0.72 https://tomcat.apache.org/security-8.html#FixedinApacheTomcat8.5.5and8.0.37
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-jasperto a version that resolves this vulnerability.Fixed in 6.0.47 - Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-jasperto a version that resolves this vulnerability.Fixed in 7.0.72 - Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-jasperto a version that resolves this vulnerability.Fixed in 8.0.37 - Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-jasperto a version that resolves this vulnerability.Fixed in 8.5.5 - Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-jasperto a version that resolves this vulnerability.Fixed in 9.0.0.M10 - Upgrade
Upgrade
maven/org.apache.tomcat:jasperto a version that resolves this vulnerability.Fixed in 6.0.47 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcat-jasperto a version that resolves this vulnerability.Fixed in 7.0.72 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcat-jasperto a version that resolves this vulnerability.Fixed in 8.0.37 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcat-jasperto a version that resolves this vulnerability.Fixed in 8.5.5 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcat-jasperto a version that resolves this vulnerability.Fixed in 9.0.0.M10 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 6.0.47 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 7.0.72 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 8.5.5 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 8.0.37 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 6.0.47 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 7.0.72 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 8.5.5 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 8.0.37
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5018?
CVE-2016-5018 is classified as a moderate severity vulnerability affecting various versions of Apache Tomcat.
How do I fix CVE-2016-5018?
To fix CVE-2016-5018, update Apache Tomcat to one of the fixed versions, such as 6.0.47, 7.0.72, 8.0.37, 8.5.5, or 9.0.0.M10.
What versions of Apache Tomcat are affected by CVE-2016-5018?
CVE-2016-5018 affects Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, and 6.0.0 to 6.0.45.
What type of vulnerability is CVE-2016-5018?
CVE-2016-5018 is a security vulnerability that allows a malicious web application to bypass a configured SecurityManager in Apache Tomcat.
Who should be concerned about CVE-2016-5018?
Organizations and individuals using vulnerable versions of Apache Tomcat should be concerned about CVE-2016-5018 due to its potential security implications.