Bug 967815 (CVE-2016-0706) - VUL-0: CVE-2016-0706: tomcat6, tomcat: security manager bypass via StatusManagerServlet
Summary: VUL-0: CVE-2016-0706: tomcat6, tomcat: security manager bypass via StatusMana...
Status: RESOLVED FIXED
Alias: CVE-2016-0706
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Minor
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/162123/
Whiteboard: CVSSv2:RedHat:CVE-2016-0706:2.9:(AV:A...
Keywords:
Depends on:
Blocks:
 
Reported: 2016-02-23 12:12 UTC by Alexander Bergmann
Modified: 2018-08-23 16:08 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2016-02-23 12:12:16 UTC
http://seclists.org/bugtraq/2016/Feb/144

CVE-2016-0706 Apache Tomcat Security Manager bypass

Severity: Low

Vendor: The Apache Software Foundation

Versions Affected:
- - Apache Tomcat 6.0.0 to 6.0.44
- - Apache Tomcat 7.0.0 to 7.0.67
- - Apache Tomcat 8.0.0.RC1 to 8.0.30
- - Apache Tomcat 9.0.0.M1
- - Earlier, unsupported Tomcat versions may be affected

Description:
The StatusManagerServlet could be loaded by a web application when a
security manager was configured. This servlet would then provide the web
application with a list of all deployed applications and a list of the
HTTP request lines for all requests currently being processed. This
could have exposed sensitive information from other web applications
such as session IDs to the web application.

Mitigation:
Users of affected versions should apply one of the following mitigations
- - Upgrade to Apache Tomcat 9.0.0.M3 or later
  (9.0.0.M2 has the fix but was not released)
- - Upgrade to Apache Tomcat 8.0.32 or later
  (8.0.31 has the fix but was not released)
- - Upgrade to Apache Tomcat 7.0.68 or later
- - Upgrade to Apache Tomcat 6.0.45 or later


Credit:
This issue was discovered by The Apache Tomcat Security Team.

References:
[1] http://tomcat.apache.org/security-9.html
[2] http://tomcat.apache.org/security-8.html
[3] http://tomcat.apache.org/security-7.html
[4] http://tomcat.apache.org/security-6.html

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1311087
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-0706
Comment 1 Swamp Workflow Management 2016-02-23 23:00:47 UTC
bugbot adjusting priority
Comment 2 Swamp Workflow Management 2016-03-15 14:13:14 UTC
SUSE-SU-2016:0769-1: An update that fixes 7 vulnerabilities is now available.

Category: security (important)
Bug References: 967812,967814,967815,967964,967965,967966,967967
CVE References: CVE-2015-5174,CVE-2015-5345,CVE-2015-5346,CVE-2015-5351,CVE-2016-0706,CVE-2016-0714,CVE-2016-0763
Sources used:
SUSE Linux Enterprise Server 12-SP1 (src):    tomcat-8.0.32-3.1
Comment 3 Swamp Workflow Management 2016-03-18 18:14:09 UTC
SUSE-SU-2016:0822-1: An update that fixes 7 vulnerabilities is now available.

Category: security (important)
Bug References: 967812,967814,967815,967964,967965,967966,967967
CVE References: CVE-2015-5174,CVE-2015-5345,CVE-2015-5346,CVE-2015-5351,CVE-2016-0706,CVE-2016-0714,CVE-2016-0763
Sources used:
SUSE Linux Enterprise Server 12 (src):    tomcat-7.0.68-7.6.1
Comment 4 Swamp Workflow Management 2016-03-21 13:14:41 UTC
SUSE-SU-2016:0839-1: An update that solves four vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 934219,967815,967964,967965,967967
CVE References: CVE-2015-5174,CVE-2015-5345,CVE-2016-0706,CVE-2016-0714
Sources used:
SUSE Linux Enterprise Server 11-SP4 (src):    tomcat6-6.0.45-0.50.1
Comment 5 Swamp Workflow Management 2016-03-23 17:10:24 UTC
openSUSE-SU-2016:0865-1: An update that fixes 7 vulnerabilities is now available.

Category: security (important)
Bug References: 967812,967814,967815,967964,967965,967966,967967
CVE References: CVE-2015-5174,CVE-2015-5345,CVE-2015-5346,CVE-2015-5351,CVE-2016-0706,CVE-2016-0714,CVE-2016-0763
Sources used:
openSUSE Leap 42.1 (src):    tomcat-8.0.32-5.1
Comment 7 Marcus Meissner 2017-07-03 13:19:49 UTC
erleased