Back

HIGH

tomcat: unrestricted access to global resources

Published Aug 10, 2017

Description

The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global JNDI resources to those resources explicitly linked to the web application. Therefore, it was possible for a web application to access any global JNDI resource whether an explicit ResourceLink had been configured or not.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (54)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Aug 10, 2017
Updated Sep 17, 2024
Reserved Aug 12, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Oct 27, 2016
GHSA-Q6X7-F33R-3WXX