Improper Input Validation Affecting tomcat package, versions [,6.0.35-1)[7.0.0,7.0.52-1)[7.0.0,7.0.56-3)[8.0.0,8.0.14-1)[8.0.0,8.0.32-1)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
9.78% (96th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-TOMCAT-2382458
  • published26 Jan 2022
  • disclosed3 Oct 2016
  • creditUnknown

Introduced: 3 Oct 2016

CVE-2016-1240  (opens in a new tab)
CWE-20  (opens in a new tab)

How to fix?

Upgrade tomcat to version 6.0.35-1, 7.0.52-1, 7.0.56-3, 8.0.14-1, 8.0.32-1 or higher.

Overview

Affected versions of this package are vulnerable to Improper Input Validation. The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debian jessie and the tomcat6 and libtomcat6-java packages before 6.0.35-1ubuntu3.8 on Ubuntu 12.04 LTS, the tomcat7 and libtomcat7-java packages before 7.0.52-1ubuntu0.7 on Ubuntu 14.04 LTS, and tomcat8 and libtomcat8-java packages before 8.0.32-1ubuntu1.2 on Ubuntu 16.04 LTS allows local users with access to the tomcat account to gain root privileges via a symlink attack on the Catalina log file, as demonstrated by /var/log/tomcat7/catalina.out.

CVSS Base Scores

version 3.1