QID 996852
Date Published: 2024-01-24
QID 996852: Java (Maven) Security Update for org.apache.tomcat:tomcat (GHSA-cw54-59pw-4g8c)
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-cw54-59pw-4g8c for updates and patch information.
Vendor References
- GHSA-cw54-59pw-4g8c -
github.com/advisories/GHSA-cw54-59pw-4g8c
CVEs related to QID 996852
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-cw54-59pw-4g8c | org.apache.tomcat:tomcat |
|