CVE
- Id
- 87010
- CVE No.
- CVE-2016-0714
- Status
- Candidate
- Description
- The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 mishandles session attributes, which allows remote authenticated users to bypass intended SecurityManager restrictions and execute arbitrary code in a privileged context via a web application that places a crafted object in a session.
- Phase
- Assigned (20151216)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
825 | JVNDB-2016-001598 | Android のカーネルの Qualcomm Wi-Fi ドライバにおける権限を取得される脆弱性 | Android のカーネルの Qualcomm Wi-Fi ドライバには、権限を取得される脆弱性が存在します。 | CVE-2016-0806 | 87010 | 7.2 | http://jvndb.jvn.jp/ja/contents/2016/JVNDB-2016-001598.html | View |