CVE-2016-5425: High severity tomcat vulnerability
It was discovered that the Tomcat packages installed configuration file /usr/lib/tmpfiles.d/tomcat.conf writeable to the tomcat group. A member of the group or a malicious web application deployed on Tomcat could use this flaw to escalate their privileges.
Other sources
It was reported that Tomcat packages in Red Hat Enterprise Linux 7 are vulnerable to local privilege escalation from tomcat group user to root. Tomcat configuration file located at /usr/lib/tmpfiles.d/tomcat.conf can be modified by any user belonging to tomcat group. This file is used by /usr/bin/systemd-tmpfiles service to create temporary files.
As the systemd-tmpfiles service runs with root permissions, this enables the tomcat user to gain root privileges by editing the /usr/lib/tmpfiles.d/tomcat.conf file to contain a line which will cause the systemd-tmpfiles to create files within arbitrary system directory and arbitrary permissions.
External Reference:
http://legalhackers.com/advisories/Tomcat-RedHat-based-Root-Privilege-Escalation-Exploit.txt
— Red Hat
The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain root privileges by leveraging membership in the tomcat group.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5425?
CVE-2016-5425 is classified with a moderate severity level, allowing privilege escalation.
How do I fix CVE-2016-5425?
To fix CVE-2016-5425, update the Tomcat package to a version that is not affected, specifically 0:7.0.54-8.el7_2 or later.
What systems are affected by CVE-2016-5425?
CVE-2016-5425 affects certain versions of the Tomcat package installed on Red Hat-based systems.
What is the impact of CVE-2016-5425?
The impact of CVE-2016-5425 includes the potential for unauthorized privilege escalation by group members or malicious applications.
Is there a known exploit for CVE-2016-5425?
Yes, there are known exploits that leverage CVE-2016-5425 to gain elevated privileges on affected systems.