Back

CRITICAL

tomcat: Calls to application listeners did not use the appropriate facade object

Published Apr 17, 2017

Description

While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use the appropriate facade object. When running an untrusted application under a SecurityManager, it was therefore possible for that untrusted application to retain a reference to the request or response object and thereby access and/or modify information associated with another web application.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (43)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Apr 17, 2017
Updated Aug 5, 2024
Reserved Jan 29, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Apr 10, 2017
GHSA-3VX3-XF6Q-R5XP