CVE-2016-6796: High severity Apache Tomcat vulnerability
A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via manipulation of the configuration parameters for the JSP Servlet.
Other sources
The following flaw was found in Tomcat:
A malicious web application was able to bypass a configured SecurityManager via manipulation of the configuration parameters for the JSP Servlet.
Upstream patches:
6.0.47: https://svn.apache.org/viewvc?view=rev&rev=1758496 https://svn.apache.org/viewvc?view=rev&rev=1763237
7.0.72: https://svn.apache.org/viewvc?view=rev&rev=1758495 https://svn.apache.org/viewvc?view=rev&rev=1763236
8.5.5: https://svn.apache.org/viewvc?view=rev&rev=1758493
8.0.37: https://svn.apache.org/viewvc?view=rev&rev=1758494 https://svn.apache.org/viewvc?view=rev&rev=1763234
External References:
https://tomcat.apache.org/security-6.html#FixedinApacheTomcat6.0.47 https://tomcat.apache.org/security-7.html#FixedinApacheTomcat7.0.72 https://tomcat.apache.org/security-8.html#FixedinApacheTomcat8.5.5and8.0.37
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 6.0.47 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 7.0.72 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 8.5.5 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 8.0.37 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcatto a version that resolves this vulnerability.Fixed in 6.0.46 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcatto a version that resolves this vulnerability.Fixed in 7.0.71 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcatto a version that resolves this vulnerability.Fixed in 8.0.37 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcatto a version that resolves this vulnerability.Fixed in 8.5.5 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcatto a version that resolves this vulnerability.Fixed in 9.0.0.M10
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6796?
CVE-2016-6796 has been classified as a high severity vulnerability due to its ability to bypass security restrictions.
How do I fix CVE-2016-6796?
To fix CVE-2016-6796, upgrade to Apache Tomcat version 6.0.47, 7.0.72, 8.0.37, 8.5.5, or 9.0.0.M10.
Which versions of Apache Tomcat are affected by CVE-2016-6796?
CVE-2016-6796 affects Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, and 6.0.0 to 6.0.45.
Is CVE-2016-6796 related to the JSP Servlet configuration?
Yes, CVE-2016-6796 specifically allows a malicious web application to bypass the configured SecurityManager through manipulation of JSP Servlet configuration parameters.
What impact does CVE-2016-6796 have on my application?
The impact of CVE-2016-6796 could lead to unauthorized access or modification of application data if exploited successfully.