logo

CVE-2014-7810 org.apache.tomcat:tomcat

Package

Manager: maven
Name: org.apache.tomcat:tomcat
Vulnerable Version: >=6.0.0 <6.0.44 || >=7.0.0 <7.0.58 || >=8.0.0 <8.0.16

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

EPSS: 0.09321 pctl0.9245

Details

Improper Access Control in Apache Tomcat The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypass a SecurityManager protection mechanism via a web application that leverages use of incorrect privileges during EL evaluation.

Metadata

Created: 2022-05-14T01:10:17Z
Modified: 2022-07-06T21:05:15Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-4c43-cwvx-9crh/GHSA-4c43-cwvx-9crh.json
CWE IDs: ["CWE-284"]
Alternative ID: GHSA-4c43-cwvx-9crh
Finding: F039
Auto approve: 1