Oval Definition:oval:com.ubuntu.precise:def:20160714000
Revision Date:2016-02-24Version:1
Title:CVE-2016-0714 on Ubuntu 12.04 LTS (precise) - medium.
Description:The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 mishandles session attributes, which allows remote authenticated users to bypass intended SecurityManager restrictions and execute arbitrary code in a privileged context via a web application that places a crafted object in a session.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2016-0714
Platform(s):Ubuntu 12.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 12.04 LTS (precise) is installed.
  • AND Package Information
  • The 'tomcat6' package in precise was vulnerable but has been fixed (note: '6.0.35-1ubuntu3.7').
  • OR The 'tomcat7' package in precise is affected and needs fixing.
  • BACK