CVE-2016-6797: High severity Apache Tomcat vulnerability
Last updated 18 August 2025
Other sources
The following flaw was reported in Tomcat:
The ResourceLinkFactory did not limit web application access to global JNDI resources to those resources explicitly linked to the web application. Therefore, it was possible for a web application to access any global JNDI resource whether an explicit ResourceLink had been configured or not.
Upstream patches:
6.0.47: https://svn.apache.org/viewvc?view=revision&revision=1757285 7.0.72: https://svn.apache.org/viewvc?view=revision&revision=1757275 8.5.5: https://svn.apache.org/viewvc?view=revision&revision=1757272 8.0.37: https://svn.apache.org/viewvc?view=revision&revision=1757273
— Red Hat
The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9. ...
— Debian
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.apache.tomcat:tomcatto a version that resolves this vulnerability.Fixed in 7.0.72 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcatto a version that resolves this vulnerability.Fixed in 8.0.37 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcatto a version that resolves this vulnerability.Fixed in 8.5.5 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcatto a version that resolves this vulnerability.Fixed in 9.0.0.M10 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 6.0.47 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 7.0.72 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 8.5.5 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 8.0.37 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 6.0.47 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 7.0.72 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 8.0.37 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 8.5.5
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6797?
The severity of CVE-2016-6797 is considered medium due to its potential for unauthorized access to global JNDI resources.
How do I fix CVE-2016-6797?
To fix CVE-2016-6797, update to Tomcat version 6.0.47, 7.0.72, 8.0.37, 8.5.5, or 9.0.0.M10.
Which versions of Tomcat are affected by CVE-2016-6797?
Affected versions of Tomcat include 6.0.0 to 6.0.45, 7.0.0 to 7.0.70, 8.0.0 to 8.0.36, and 8.5.0 to 8.5.4.
What is the risk associated with CVE-2016-6797?
The risk associated with CVE-2016-6797 is that a vulnerable web application could access sensitive global JNDI resources without proper authorization.
Is there a workaround for CVE-2016-6797?
A potential workaround for CVE-2016-6797 includes restricting access to JNDI resources through appropriate security configurations.