{"id":"CVE-2016-5018","details":"In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able to bypass a configured SecurityManager via a Tomcat utility method that was accessible to web applications.","aliases":["GHSA-4v3g-g84w-hv7r"],"modified":"2026-04-11T12:04:21.483857Z","published":"2017-08-10T16:29:00.407Z","related":["MGASA-2016-0367","SUSE-SU-2016:3079-1","SUSE-SU-2016:3081-1","SUSE-SU-2017:1632-1","SUSE-SU-2017:1660-1"],"database_specific":{"unresolved_ranges":[{"cpe":"cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"6.0.0"},{"last_affected":"6.0.45"},{"introduced":"8.0"},{"last_affected":"8.0.36"}],"source":"CPE_FIELD"},{"cpe":"cpe:2.3:a:oracle:tekelec_platform_distribution:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"7.4.0"},{"last_affected":"7.7.1"}],"source":"CPE_FIELD"},{"cpe":"cpe:2.3:a:redhat:jboss_enterprise_application_platform:6.4:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"6.4"}],"source":"CPE_FIELD"},{"cpe":"cpe:2.3:a:redhat:jboss_enterprise_web_server:3.0.0:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"3.0.0"}],"source":"CPE_FIELD"},{"cpe":"cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*","extracted_events":[{"last_affected":"16.04"}],"source":"CPE_FIELD"},{"cpe":"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"8.0"}],"source":"CPE_FIELD"},{"cpe":"cpe:2.3:o:redhat:enterprise_linux_eus:7.4:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"7.4"}],"source":"CPE_FIELD"},{"cpe":"cpe:2.3:o:redhat:enterprise_linux_eus:7.5:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"7.5"}],"source":"CPE_FIELD"},{"cpe":"cpe:2.3:o:redhat:enterprise_linux_eus:7.6:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"7.6"}],"source":"CPE_FIELD"},{"cpe":"cpe:2.3:o:redhat:enterprise_linux_eus:7.7:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"7.7"}],"source":"CPE_FIELD"},{"cpe":"cpe:2.3:o:redhat:enterprise_linux_server_aus:7.4:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"7.4"}],"source":"CPE_FIELD"},{"cpe":"cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"7.6"}],"source":"CPE_FIELD"},{"cpe":"cpe:2.3:o:redhat:enterprise_linux_server_aus:7.7:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"7.7"}],"source":"CPE_FIELD"},{"cpe":"cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"7.6"}],"source":"CPE_FIELD"},{"cpe":"cpe:2.3:o:redhat:enterprise_linux_server_tus:7.7:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"7.7"}],"source":"CPE_FIELD"}]},"references":[{"type":"WEB","url":"http://www.securityfocus.com/bid/93942"},{"type":"WEB","url":"http://www.securitytracker.com/id/1037142"},{"type":"WEB","url":"http://www.securitytracker.com/id/1038757"},{"type":"WEB","url":"https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113%40%3Cdev.tomcat.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b%40%3Cdev.tomcat.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424%40%3Cdev.tomcat.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/9b3a63a20c87179815fdea14f6766853bafe79a0042dc0b4aa878a9e%40%3Cannounce.tomcat.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc%40%3Cdev.tomcat.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95%40%3Cdev.tomcat.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb%40%3Cdev.tomcat.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c%40%3Cdev.tomcat.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b%40%3Cdev.tomcat.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2017-0457.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2017-1551.html"},{"type":"ADVISORY","url":"http://www.debian.org/security/2016/dsa-3720"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:0455"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:0456"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:1548"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:1549"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:1550"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:1552"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:2247"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20180605-0001/"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/4557-1/"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuoct2021.html"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/155873/Tomcat-9.0.0.M1-Sandbox-Escape.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/tomcat","events":[{"introduced":"e498667bd7811e846771a852b16ce9f1e524b81b"},{"last_affected":"ff181ab22b2b18e77ab9e0f0c2cfe5cfa59c844c"},{"introduced":"e37b977db6f47e4380ad67114a49e8568951c953"},{"last_affected":"3e5565173dfe107f90419ab63bd4e2e7edc9deb4"},{"introduced":"0"},{"last_affected":"29b07def810d335012e738b22ab44d4e232b50d1"},{"last_affected":"18b014d8691909be6153ae7db022a6c35f9c93ea"},{"last_affected":"d1dc05e934e089ea8907998cf850760017a0ed82"},{"last_affected":"fd7f13635e6855f6ba3fead0bf37ba2fbf8b68cf"},{"last_affected":"c7b84102600d600bcc527560d9c4d10c3fd440ab"},{"last_affected":"d8ebf61e51b4455e3c226751e492a533f9002d48"},{"last_affected":"aba238718ac9b149d25feaa9a14ecad3b0e3a5e2"},{"last_affected":"fe854ab1f111396458d98fa2ab08c693ce9407e1"},{"last_affected":"45f8fd74cdb96490fab8709263a4d862f0d429cf"},{"last_affected":"e498667bd7811e846771a852b16ce9f1e524b81b"}],"database_specific":{"cpe":["cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.0:milestone1:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.0:milestone2:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.0:milestone3:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.0:milestone4:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.0:milestone5:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.0:milestone6:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.0:milestone7:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.0:milestone8:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.0:milestone9:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.0.0"},{"last_affected":"7.0.70"},{"introduced":"8.5.0"},{"last_affected":"8.5.4"},{"introduced":"0"},{"last_affected":"9.0.0-milestone1"},{"last_affected":"9.0.0-milestone2"},{"last_affected":"9.0.0-milestone3"},{"last_affected":"9.0.0-milestone4"},{"last_affected":"9.0.0-milestone5"},{"last_affected":"9.0.0-milestone6"},{"last_affected":"9.0.0-milestone7"},{"last_affected":"9.0.0-milestone8"},{"last_affected":"9.0.0-milestone9"},{"last_affected":"7.0"}],"source":"CPE_FIELD"}}],"versions":["7.0.0","7.0.70","8.5.4","9.0.0-M1","9.0.0-M2","9.0.0-M3","9.0.0-M4","9.0.0-M5","9.0.0-M6","9.0.0-M7","9.0.0-M8","9.0.0-M9"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-5018.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}