vendor:
Tomcat
by:
Harrison Neal, PatchAdvisor
9.1
CVSS
CRITICAL
Sandbox Escape
501
CWE
Product Name: Tomcat
Affected Version From: 8.0.36
Affected Version To: 8.0.36
Patch Exists: NO
Related CWE: CVE-2016-5018
CPE: a:apache:tomcat:8.0.36
Metasploit:
https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp2-cve-2016-5018/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2016-5018/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp1-cve-2016-5018/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2016-5018/, https://www.rapid7.com/db/vulnerabilities/ubuntu-usn-3177-2/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2016-5018/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2016-5018/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2016-5018/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2016-5018/, https://www.rapid7.com/db/vulnerabilities/amazon_linux-cve-2016-5018/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2016-5018/, https://www.rapid7.com/db/vulnerabilities/apache-tomcat-cve-2016-5018/, https://www.rapid7.com/db/vulnerabilities/freebsd-cve-2016-5018/
Platforms Tested: Windows
2020
Tomcat proprietaryEvaluate 9.0.0.M1 – Sandbox Escape
Tomcat proprietaryEvaluate/introspecthelper Sandbox Escape
Mitigation:
Unknown