← Back

CVE-2016-5425

nvd nist
Published: Oct 13, 2016Modified: May 6, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain root privileges by leveraging membership in the tomcat group.

Affected (1)

Products: Apache: Tomcat
1 product
Tomcat
Configuration A
1 vulnerable · 22 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Oracle
Instantis Enterprisetrack
Version 17.1
Oracle
Instantis Enterprisetrack
Version 17.2
Oracle
Instantis Enterprisetrack
Version 17.3
Oracle
Linux
Version 7
Redhat
Enterprise Linux Desktop
Version 7.0
Redhat
Enterprise Linux Server
Version 7.0
Redhat
Enterprise Linux Server Aus
Version 7.2
Redhat
Enterprise Linux Server Aus
Version 7.3
Redhat
Enterprise Linux Server Aus
Version 7.4
Redhat
Enterprise Linux Server Aus
Version 7.6
Redhat
Enterprise Linux Server Aus
Version 7.7
Redhat
Enterprise Linux Server Eus
Version 7.2
Redhat
Enterprise Linux Server Eus
Version 7.3
Redhat
Enterprise Linux Server Eus
Version 7.4
Redhat
Enterprise Linux Server Eus
Version 7.5
Redhat
Enterprise Linux Server Eus
Version 7.6
Redhat
Enterprise Linux Server Eus
Version 7.7
Redhat
Enterprise Linux Server Tus
Version 7.2
Redhat
Enterprise Linux Server Tus
Version 7.3
Redhat
Enterprise Linux Server Tus
Version 7.6
Redhat
Enterprise Linux Server Tus
Version 7.7
Redhat
Enterprise Linux Workstation
Version 7.0

References (20)

Source: secalert@redhat.com
ExploitThird Party AdvisoryVDB Entry
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Third Party AdvisoryVDB Entry
Source: secalert@redhat.com
Third Party AdvisoryVDB Entry
Source: secalert@redhat.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.