CVE-2014-7810 – org.apache.tomcat:tomcat
Package
Manager: maven
Name: org.apache.tomcat:tomcat
Vulnerable Version: >=6.0.0 <6.0.44 || >=7.0.0 <7.0.58 || >=8.0.0 <8.0.16
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.09321 pctl0.9245
Details
Improper Access Control in Apache Tomcat The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypass a SecurityManager protection mechanism via a web application that leverages use of incorrect privileges during EL evaluation.
Metadata
Created: 2022-05-14T01:10:17Z
Modified: 2022-07-06T21:05:15Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-4c43-cwvx-9crh/GHSA-4c43-cwvx-9crh.json
CWE IDs: ["CWE-284"]
Alternative ID: GHSA-4c43-cwvx-9crh
Finding: F039
Auto approve: 1