[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2016-6797 -- tomcat6

ID: oval:org.secpod.oval:def:1900483Date: (C)2019-03-29   (M)2023-12-20
Class: VULNERABILITYFamily: unix




The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to6.0.45 did not limit web application access to global JNDI resources to those resources explicitly linked to the web application. Therefore, it was possible for a web application to access any global JNDI resource whether an explicit ResourceLink had been configured or not.

Platform:
Ubuntu 16.04
Ubuntu 14.04
Product:
tomcat6
Reference:
CVE-2016-6797
CVE    1
CVE-2016-6797
CPE    167
cpe:/a:apache:tomcat:7.0.70
cpe:/a:apache:tomcat:7.0.62
cpe:/a:apache:tomcat:7.0.61
cpe:/a:apache:tomcat:7.0.64
...

© SecPod Technologies