CVE-2016-6794 -- tomcat6ID: oval:org.secpod.oval:def:1900514 | Date: (C)2019-02-27 (M)2023-12-20 |
Class: VULNERABILITY | Family: unix |
When a Security Manager is configured, a web application"s ability to readsystem properties should be controlled by the Security Manager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, 6.0.0 to 6.0.45 the system property replacement feature for configuration files could be used by a malicious web application to bypass the Security Manager and read system properties that should not be visible.
Platform: |
Ubuntu 16.04 |
Ubuntu 14.04 |