CVE Vulnerabilities

CVE-2016-0714

Published: Feb 25, 2016 | Modified: Apr 12, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
6.8 MODERATE
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
8.8 MODERATE
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 mishandles session attributes, which allows remote authenticated users to bypass intended SecurityManager restrictions and execute arbitrary code in a privileged context via a web application that places a crafted object in a session.

Affected Software

NameVendorStart VersionEnd Version
TomcatApache6.0.0 (including)6.0.0 (including)
TomcatApache6.0.0-alpha (including)6.0.0-alpha (including)
TomcatApache6.0.1 (including)6.0.1 (including)
TomcatApache6.0.1-alpha (including)6.0.1-alpha (including)
TomcatApache6.0.2 (including)6.0.2 (including)
TomcatApache6.0.2-alpha (including)6.0.2-alpha (including)
TomcatApache6.0.2-beta (including)6.0.2-beta (including)
TomcatApache6.0.4 (including)6.0.4 (including)
TomcatApache6.0.4-alpha (including)6.0.4-alpha (including)
TomcatApache6.0.10 (including)6.0.10 (including)
TomcatApache6.0.11 (including)6.0.11 (including)
TomcatApache6.0.13 (including)6.0.13 (including)
TomcatApache6.0.14 (including)6.0.14 (including)
TomcatApache6.0.16 (including)6.0.16 (including)
TomcatApache6.0.18 (including)6.0.18 (including)
TomcatApache6.0.20 (including)6.0.20 (including)
TomcatApache6.0.24 (including)6.0.24 (including)
TomcatApache6.0.26 (including)6.0.26 (including)
TomcatApache6.0.28 (including)6.0.28 (including)
TomcatApache6.0.29 (including)6.0.29 (including)
TomcatApache6.0.30 (including)6.0.30 (including)
TomcatApache6.0.32 (including)6.0.32 (including)
TomcatApache6.0.33 (including)6.0.33 (including)
TomcatApache6.0.35 (including)6.0.35 (including)
TomcatApache6.0.36 (including)6.0.36 (including)
TomcatApache6.0.37 (including)6.0.37 (including)
TomcatApache6.0.39 (including)6.0.39 (including)
TomcatApache6.0.41 (including)6.0.41 (including)
TomcatApache6.0.43 (including)6.0.43 (including)
TomcatApache6.0.44 (including)6.0.44 (including)
TomcatApache7.0.0-beta (including)7.0.0-beta (including)
TomcatApache7.0.2-beta (including)7.0.2-beta (including)
TomcatApache7.0.4-beta (including)7.0.4-beta (including)
TomcatApache7.0.5-beta (including)7.0.5-beta (including)
TomcatApache7.0.6 (including)7.0.6 (including)
TomcatApache7.0.10 (including)7.0.10 (including)
TomcatApache7.0.11 (including)7.0.11 (including)
TomcatApache7.0.12 (including)7.0.12 (including)
TomcatApache7.0.14 (including)7.0.14 (including)
TomcatApache7.0.16 (including)7.0.16 (including)
TomcatApache7.0.19 (including)7.0.19 (including)
TomcatApache7.0.20 (including)7.0.20 (including)
TomcatApache7.0.21 (including)7.0.21 (including)
TomcatApache7.0.22 (including)7.0.22 (including)
TomcatApache7.0.23 (including)7.0.23 (including)
TomcatApache7.0.25 (including)7.0.25 (including)
TomcatApache7.0.26 (including)7.0.26 (including)
TomcatApache7.0.27 (including)7.0.27 (including)
TomcatApache7.0.28 (including)7.0.28 (including)
TomcatApache7.0.29 (including)7.0.29 (including)
TomcatApache7.0.30 (including)7.0.30 (including)
TomcatApache7.0.32 (including)7.0.32 (including)
TomcatApache7.0.33 (including)7.0.33 (including)
TomcatApache7.0.34 (including)7.0.34 (including)
TomcatApache7.0.35 (including)7.0.35 (including)
TomcatApache7.0.37 (including)7.0.37 (including)
TomcatApache7.0.39 (including)7.0.39 (including)
TomcatApache7.0.40 (including)7.0.40 (including)
TomcatApache7.0.41 (including)7.0.41 (including)
TomcatApache7.0.42 (including)7.0.42 (including)
TomcatApache7.0.47 (including)7.0.47 (including)
TomcatApache7.0.50 (including)7.0.50 (including)
TomcatApache7.0.52 (including)7.0.52 (including)
TomcatApache7.0.53 (including)7.0.53 (including)
TomcatApache7.0.54 (including)7.0.54 (including)
TomcatApache7.0.55 (including)7.0.55 (including)
TomcatApache7.0.56 (including)7.0.56 (including)
TomcatApache7.0.57 (including)7.0.57 (including)
TomcatApache7.0.59 (including)7.0.59 (including)
TomcatApache7.0.61 (including)7.0.61 (including)
TomcatApache7.0.62 (including)7.0.62 (including)
TomcatApache7.0.63 (including)7.0.63 (including)
TomcatApache7.0.64 (including)7.0.64 (including)
TomcatApache7.0.65 (including)7.0.65 (including)
TomcatApache7.0.67 (including)7.0.67 (including)
TomcatApache8.0.0-rc1 (including)8.0.0-rc1 (including)
TomcatApache8.0.0-rc10 (including)8.0.0-rc10 (including)
TomcatApache8.0.0-rc3 (including)8.0.0-rc3 (including)
TomcatApache8.0.0-rc5 (including)8.0.0-rc5 (including)
TomcatApache8.0.1 (including)8.0.1 (including)
TomcatApache8.0.3 (including)8.0.3 (including)
TomcatApache8.0.11 (including)8.0.11 (including)
TomcatApache8.0.12 (including)8.0.12 (including)
TomcatApache8.0.14 (including)8.0.14 (including)
TomcatApache8.0.15 (including)8.0.15 (including)
TomcatApache8.0.17 (including)8.0.17 (including)
TomcatApache8.0.18 (including)8.0.18 (including)
TomcatApache8.0.20 (including)8.0.20 (including)
TomcatApache8.0.21 (including)8.0.21 (including)
TomcatApache8.0.22 (including)8.0.22 (including)
TomcatApache8.0.23 (including)8.0.23 (including)
TomcatApache8.0.24 (including)8.0.24 (including)
TomcatApache8.0.26 (including)8.0.26 (including)
TomcatApache8.0.27 (including)8.0.27 (including)
TomcatApache8.0.28 (including)8.0.28 (including)
TomcatApache8.0.29 (including)8.0.29 (including)
TomcatApache8.0.30 (including)8.0.30 (including)
TomcatApache9.0.0-milestone1 (including)9.0.0-milestone1 (including)
Red Hat Enterprise Linux 6RedHattomcat6-0:6.0.24-98.el6_8*
Red Hat Enterprise Linux 7RedHattomcat-0:7.0.69-10.el7*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHattomcat7-0:7.0.54-23_patch_05.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 7RedHattomcat7-0:7.0.54-23_patch_05.ep6.el7*
Red Hat JBoss Web Server 2.1RedHattomcat7*
Red Hat JBoss Web Server 3.0RedHat*
Red Hat JBoss Web Server 3 for RHEL 6RedHathttpd24-0:2.4.6-61.ep7.el6*
Red Hat JBoss Web Server 3 for RHEL 6RedHatmod_security-jws3-0:2.8.0-7.GA.ep7.el6*
Red Hat JBoss Web Server 3 for RHEL 6RedHattomcat7-0:7.0.59-50_patch_01.ep7.el6*
Red Hat JBoss Web Server 3 for RHEL 6RedHattomcat8-0:8.0.18-61_patch_01.ep7.el6*
Red Hat JBoss Web Server 3 for RHEL 7RedHathttpd24-0:2.4.6-61.ep7.el7*
Red Hat JBoss Web Server 3 for RHEL 7RedHatmod_security-jws3-0:2.8.0-7.GA.ep7.el7*
Red Hat JBoss Web Server 3 for RHEL 7RedHattomcat7-0:7.0.59-50_patch_01.ep7.el7*
Red Hat JBoss Web Server 3 for RHEL 7RedHattomcat8-0:8.0.18-61_patch_01.ep7.el7*
Tomcat6Ubuntuesm-apps/xenial*
Tomcat6Ubuntuesm-infra-legacy/trusty*
Tomcat6Ubuntuprecise*
Tomcat6Ubuntutrusty*
Tomcat6Ubuntutrusty/esm*
Tomcat6Ubuntuupstream*
Tomcat6Ubuntuwily*
Tomcat6Ubuntuxenial*
Tomcat7Ubuntuesm-infra-legacy/trusty*
Tomcat7Ubuntuprecise*
Tomcat7Ubuntutrusty*
Tomcat7Ubuntutrusty/esm*
Tomcat7Ubuntuupstream*
Tomcat7Ubuntuwily*
Tomcat8Ubuntuupstream*
Tomcat8Ubuntuwily*

References