CVE-2016-5425
Apache Tomcat 8/7/6 (RedHat Based Distros) - Local Privilege Escalation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
5Exploited in Wild
-Decision
Descriptions
The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain root privileges by leveraging membership in the tomcat group.
El paquete Tomcat en Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux y posiblemente en otros productos distribuidos por Linux utiliza permisos débiles para /usr/lib/tmpfiles.d/tomcat.conf, lo que permite a usuarios locales obtener privilegios de root aprovechando su pertenencia al grupo tomcat.
It was discovered that the Tomcat packages installed configuration file /usr/lib/tmpfiles.d/tomcat.conf writeable to the tomcat group. A member of the group or a malicious web application deployed on Tomcat could use this flaw to escalate their privileges.
Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages technologies. Security Fix: It was discovered that the Tomcat packages installed configuration file /usr/lib/tmpfiles.d/tomcat.conf writeable to the tomcat group. A member of the group or a malicious web application deployed on Tomcat could use this flaw to escalate their privileges. It was discovered that the Tomcat packages installed certain configuration files read by the Tomcat initialization script as writeable to the tomcat group. A member of the group or a malicious web application deployed on Tomcat could use this flaw to escalate their privileges.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-06-10 CVE Reserved
- 2016-10-10 CVE Published
- 2016-10-10 First Exploit
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-276: Incorrect Default Permissions
- CWE-284: Improper Access Control
CAPEC
References (15)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2016/10/10/2 | Mailing List |
|
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.html | Third Party Advisory |
|
http://www.securityfocus.com/bid/93472 | Third Party Advisory | |
http://www.securitytracker.com/id/1036979 | Third Party Advisory | |
https://lists.apache.org/thread.html/6b414817c2b0bf351138911c8c922ec5dd577ebc0b9a7f42d705752d%40%3Cissues.activemq.apache.org%3E | Mailing List | |
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html | Third Party Advisory |
|
https://www.freedesktop.org/software/systemd/man/tmpfiles.d.html |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2016-2046.html | 2023-02-12 | |
https://access.redhat.com/security/cve/CVE-2016-5425 | 2016-10-10 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1362545 | 2016-10-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | - | - |
Affected
| in | Oracle Search vendor "Oracle" | Instantis Enterprisetrack Search vendor "Oracle" for product "Instantis Enterprisetrack" | 17.1 Search vendor "Oracle" for product "Instantis Enterprisetrack" and version "17.1" | - |
Safe
|
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | - | - |
Affected
| in | Oracle Search vendor "Oracle" | Instantis Enterprisetrack Search vendor "Oracle" for product "Instantis Enterprisetrack" | 17.2 Search vendor "Oracle" for product "Instantis Enterprisetrack" and version "17.2" | - |
Safe
|
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | - | - |
Affected
| in | Oracle Search vendor "Oracle" | Instantis Enterprisetrack Search vendor "Oracle" for product "Instantis Enterprisetrack" | 17.3 Search vendor "Oracle" for product "Instantis Enterprisetrack" and version "17.3" | - |
Safe
|
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | - | - |
Affected
| in | Oracle Search vendor "Oracle" | Linux Search vendor "Oracle" for product "Linux" | 7 Search vendor "Oracle" for product "Linux" and version "7" | - |
Safe
|
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | - | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Desktop Search vendor "Redhat" for product "Enterprise Linux Desktop" | 7.0 Search vendor "Redhat" for product "Enterprise Linux Desktop" and version "7.0" | - |
Safe
|
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | - | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Server Search vendor "Redhat" for product "Enterprise Linux Server" | 7.0 Search vendor "Redhat" for product "Enterprise Linux Server" and version "7.0" | - |
Safe
|
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | - | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Server Aus Search vendor "Redhat" for product "Enterprise Linux Server Aus" | 7.2 Search vendor "Redhat" for product "Enterprise Linux Server Aus" and version "7.2" | - |
Safe
|
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | - | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Server Aus Search vendor "Redhat" for product "Enterprise Linux Server Aus" | 7.3 Search vendor "Redhat" for product "Enterprise Linux Server Aus" and version "7.3" | - |
Safe
|
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | - | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Server Aus Search vendor "Redhat" for product "Enterprise Linux Server Aus" | 7.4 Search vendor "Redhat" for product "Enterprise Linux Server Aus" and version "7.4" | - |
Safe
|
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | - | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Server Aus Search vendor "Redhat" for product "Enterprise Linux Server Aus" | 7.6 Search vendor "Redhat" for product "Enterprise Linux Server Aus" and version "7.6" | - |
Safe
|
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | - | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Server Aus Search vendor "Redhat" for product "Enterprise Linux Server Aus" | 7.7 Search vendor "Redhat" for product "Enterprise Linux Server Aus" and version "7.7" | - |
Safe
|
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | - | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Server Eus Search vendor "Redhat" for product "Enterprise Linux Server Eus" | 7.2 Search vendor "Redhat" for product "Enterprise Linux Server Eus" and version "7.2" | - |
Safe
|
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | - | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Server Eus Search vendor "Redhat" for product "Enterprise Linux Server Eus" | 7.3 Search vendor "Redhat" for product "Enterprise Linux Server Eus" and version "7.3" | - |
Safe
|
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | - | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Server Eus Search vendor "Redhat" for product "Enterprise Linux Server Eus" | 7.4 Search vendor "Redhat" for product "Enterprise Linux Server Eus" and version "7.4" | - |
Safe
|
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | - | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Server Eus Search vendor "Redhat" for product "Enterprise Linux Server Eus" | 7.5 Search vendor "Redhat" for product "Enterprise Linux Server Eus" and version "7.5" | - |
Safe
|
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | - | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Server Eus Search vendor "Redhat" for product "Enterprise Linux Server Eus" | 7.6 Search vendor "Redhat" for product "Enterprise Linux Server Eus" and version "7.6" | - |
Safe
|
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | - | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Server Eus Search vendor "Redhat" for product "Enterprise Linux Server Eus" | 7.7 Search vendor "Redhat" for product "Enterprise Linux Server Eus" and version "7.7" | - |
Safe
|
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | - | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Server Tus Search vendor "Redhat" for product "Enterprise Linux Server Tus" | 7.2 Search vendor "Redhat" for product "Enterprise Linux Server Tus" and version "7.2" | - |
Safe
|
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | - | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Server Tus Search vendor "Redhat" for product "Enterprise Linux Server Tus" | 7.3 Search vendor "Redhat" for product "Enterprise Linux Server Tus" and version "7.3" | - |
Safe
|
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | - | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Server Tus Search vendor "Redhat" for product "Enterprise Linux Server Tus" | 7.6 Search vendor "Redhat" for product "Enterprise Linux Server Tus" and version "7.6" | - |
Safe
|
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | - | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Server Tus Search vendor "Redhat" for product "Enterprise Linux Server Tus" | 7.7 Search vendor "Redhat" for product "Enterprise Linux Server Tus" and version "7.7" | - |
Safe
|
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | - | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Workstation Search vendor "Redhat" for product "Enterprise Linux Workstation" | 7.0 Search vendor "Redhat" for product "Enterprise Linux Workstation" and version "7.0" | - |
Safe
|