Executive Summary

Informations
NameCVE-2016-6796First vendor Publication2017-08-10
VendorCveLast vendor Modification2019-04-15

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:N/I:P/A:N)
Cvss Base Score5Attack RangeNetwork
Cvss Impact Score2.9Attack ComplexityLow
Cvss Expoit Score10AuthenticationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via manipulation of the configuration parameters for the JSP Servlet.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6796

CWE : Common Weakness Enumeration

%idName
100 %CWE-254Security Features

CPE : Common Platform Enumeration

TypeDescriptionCount
Application171

Nessus® Vulnerability Scanner

DateDescription
2017-09-08Name : The remote EulerOS host is missing multiple security updates.
File : EulerOS_SA-2017-1191.nasl - Type : ACT_GATHER_INFO
2017-09-08Name : The remote EulerOS host is missing multiple security updates.
File : EulerOS_SA-2017-1192.nasl - Type : ACT_GATHER_INFO
2017-08-25Name : The remote CentOS host is missing one or more security updates.
File : centos_RHSA-2017-2247.nasl - Type : ACT_GATHER_INFO
2017-08-22Name : The remote Scientific Linux host is missing one or more security updates.
File : sl_20170802_tomcat_on_SL7_x.nasl - Type : ACT_GATHER_INFO
2017-08-09Name : The remote Oracle Linux host is missing one or more security updates.
File : oraclelinux_ELSA-2017-2247.nasl - Type : ACT_GATHER_INFO
2017-08-02Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2017-2247.nasl - Type : ACT_GATHER_INFO
2017-06-22Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2017-1549.nasl - Type : ACT_GATHER_INFO
2017-06-22Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2017-1550.nasl - Type : ACT_GATHER_INFO
2017-06-21Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2017-1552.nasl - Type : ACT_GATHER_INFO
2017-05-02Name : An application installed on the remote host is affected by multiple vulnerabi...
File : oracle_secure_global_desktop_apr_2017_cpu.nasl - Type : ACT_GATHER_INFO
2017-03-08Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2017-0455.nasl - Type : ACT_GATHER_INFO
2017-03-08Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2017-0456.nasl - Type : ACT_GATHER_INFO
2017-02-03Name : The remote Ubuntu host is missing one or more security-related patches.
File : ubuntu_USN-3177-2.nasl - Type : ACT_GATHER_INFO
2017-01-24Name : The remote Ubuntu host is missing one or more security-related patches.
File : ubuntu_USN-3177-1.nasl - Type : ACT_GATHER_INFO
2017-01-10Name : The remote FreeBSD host is missing one or more security-related updates.
File : freebsd_pkg_3ae106e2d52111e6ae1b002590263bf5.nasl - Type : ACT_GATHER_INFO
2016-12-14Name : The remote openSUSE host is missing a security update.
File : openSUSE-2016-1455.nasl - Type : ACT_GATHER_INFO
2016-12-14Name : The remote openSUSE host is missing a security update.
File : openSUSE-2016-1456.nasl - Type : ACT_GATHER_INFO
2016-12-02Name : The remote Debian host is missing a security update.
File : debian_DLA-728.nasl - Type : ACT_GATHER_INFO
2016-12-02Name : The remote Debian host is missing a security update.
File : debian_DLA-729.nasl - Type : ACT_GATHER_INFO
2016-11-22Name : The remote Debian host is missing a security-related update.
File : debian_DSA-3720.nasl - Type : ACT_GATHER_INFO
2016-11-22Name : The remote Debian host is missing a security-related update.
File : debian_DSA-3721.nasl - Type : ACT_GATHER_INFO
2016-11-21Name : The remote Fedora host is missing a security update.
File : fedora_2016-38e5b05260.nasl - Type : ACT_GATHER_INFO
2016-11-14Name : The remote Fedora host is missing a security update.
File : fedora_2016-4094bd4ad6.nasl - Type : ACT_GATHER_INFO
2016-11-14Name : The remote Fedora host is missing a security update.
File : fedora_2016-c1b01b9278.nasl - Type : ACT_GATHER_INFO
2016-11-11Name : The remote Amazon Linux AMI host is missing a security update.
File : ala_ALAS-2016-764.nasl - Type : ACT_GATHER_INFO
2016-11-04Name : The remote Apache Tomcat server is affected by multiple vulnerabilities.
File : tomcat_8_5_5.nasl - Type : ACT_GATHER_INFO

Sources (Detail)

SourceUrl
BID http://www.securityfocus.com/bid/93944
CONFIRM https://security.netapp.com/advisory/ntap-20180605-0001/
DEBIAN http://www.debian.org/security/2016/dsa-3720
MLIST https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e21...
https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930f...
https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338...
https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04cc...
https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f0...
https://lists.apache.org/thread.html/5a2105a56b2495ab70fa568f06925bd861f0d71f...
https://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba14...
https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993...
https://lists.apache.org/thread.html/88855876c33f2f9c532ffb75bfee570ccf0b17ff...
https://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a904...
https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930...
https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236...
REDHAT http://rhn.redhat.com/errata/RHSA-2017-0457.html
http://rhn.redhat.com/errata/RHSA-2017-1551.html
https://access.redhat.com/errata/RHSA-2017:0455
https://access.redhat.com/errata/RHSA-2017:0456
https://access.redhat.com/errata/RHSA-2017:1548
https://access.redhat.com/errata/RHSA-2017:1549
https://access.redhat.com/errata/RHSA-2017:1550
https://access.redhat.com/errata/RHSA-2017:1552
https://access.redhat.com/errata/RHSA-2017:2247
SECTRACK http://www.securitytracker.com/id/1037141
http://www.securitytracker.com/id/1038757

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
DateInformations
2019-04-15 21:18:59
  • Multiple Updates
2019-04-15 17:18:45
  • Multiple Updates
2019-03-25 17:18:59
  • Multiple Updates
2019-03-21 21:19:12
  • Multiple Updates
2018-06-06 09:18:44
  • Multiple Updates
2018-01-05 09:23:54
  • Multiple Updates
2017-11-04 09:23:45
  • Multiple Updates
2017-09-09 13:25:47
  • Multiple Updates
2017-08-26 13:24:55
  • Multiple Updates
2017-08-24 21:23:46
  • Multiple Updates
2017-08-23 13:25:04
  • Multiple Updates
2017-08-12 09:23:17
  • Multiple Updates
2017-08-11 09:23:19
  • First insertion