Timing Attack Affecting org.apache.tomcat:catalina package, versions [6,6.0.45]


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.32% (71st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGAPACHETOMCAT-30854
  • published28 Oct 2016
  • disclosed28 Oct 2016
  • creditThe Apache Tomcat Security Team

Introduced: 28 Oct 2016

CVE-2016-0762  (opens in a new tab)
CWE-264  (opens in a new tab)

Overview

org.apache.tomcat:catalina is a Servlet Engine Core Classes and Standard implementations.

Affected versions of this package are vulnerable to Timing Attack. The setGlobalContext method in ResourceLinkFactory.java does not consider whether callers to this method are authorized, which allows remote authenticated users to bypass intended SecurityManager restrictions and read or write to arbitrary application data, or cause a denial of service (application disruption), via a web application that sets a crafted global context.

CVSS Scores

version 3.1