VRT 391,810 CVEs tracked · 15,472 in RASP scope · data as of 23 minutes ago

CVE-2016-0714

8.8 High Out of RASP scope

Description

The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 mishandles session attributes, which allows remote authenticated users to bypass intended SecurityManager restrictions and execute arbitrary code in a privileged context via a web application that places a crafted object in a session.

CWE-264CWE-284 · Improper access control

Exploitation Status

No public exploit

Nothing published shows this CVE being exploited. The 1 repository below are public repositories under the 5-star bar: published, but with nobody other than their authors having looked.

CVSS E:U

  • CISA KEV not listed
  • CISA Vulnrichment no assessment published
  • Indexed PoC 1 indexed Published artifacts you can open, in GitHub PoC; first seen 2026-05-21.
  • EPSS 13% chance in 30 days A model prediction, not an observation. Higher than 96% of all scored CVEs.

1 of these are GitHub repositories below the 5★ evidence bar. They are listed because a person may still want to open one; they do not count toward the exploit maturity above.

IndexArtifactStarsFirst seen
GitHub PoC EXPOSURE demo target: Tomcat (CVE-2016-0714) + Apache Rave (CVE-2013-1814) + Java filter-padding deps 2026-05-21

Waratek Defense Posture

Out of RASP scope

A genuine Java vulnerability in a supported product that the agent cannot reach: a coverage gap, not an out-of-domain finding.

  • Protection none
  • Action not-needed none
  • Review human manual-review
  • Record active
Decided by manual classification : Manual classification of this CVE in the legacy dataset
Finding Manual classification marked OUT-OF-SCOPE but CVE matches known CPE products

CVSS

8.8 HIGH v3.0 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 2 metrics

VRT selects the newest version's highest entry and publishes it as cvssScore, newest rather than largest because scores are not comparable across versions, and highest rather than first because the first entry is frequently a CNA placeholder scoring 0.0 over NVD's own analysis.

VersionScoreBandVectorAssignerType
CVSS 3.0 8.8 HIGH CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H NVD Primary published
CVSS 2.0 6.5 no band published AV:N/AC:L/Au:S/C:P/I:P/A:P NVD Primary

Affected Software & Releases

🏛️ Oracle CPU Advisories & Products

AdvisoryTypeQuarterProducts Oracle named in risk matrix
Oracle Critical Patch Update July 2018 CPU 2018-Q3 Oracle Communications Applications / Security (Apache Tomcat) (12.x)
Oracle Critical Patch Update October 2017 CPU 2017-Q4 Oracle Fusion Middleware / Monitor (Apache Tomcat) (11.2.1.0.12)
Oracle Critical Patch Update April 2017 CPU 2017-Q2 Oracle Fusion Middleware / Apache Tomcat (11.1.1.8.0)
Oracle Critical Patch Update January 2017 CPU 2017-Q1 Oracle MySQL / MySQL Enterprise Monitor (3.1.4.7895 and earlier, 3.2.1.1049 and earlier)
Oracle Critical Patch Update October 2016 CPU 2016-Q4 Oracle Supply Chain Products Suite / Install (6.1, 6.2, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7)
Oracle Virtualization / Apache Tomcat (VDI prior to 3.5.3)

Indexed Oracle Components & Versions

FamilyComponentOracle's version cell (verbatim)Indexed as
Oracle Communications Applications Security (Apache Tomcat) 12.x 12
Oracle Fusion Middleware Apache Tomcat 11.1.1.8.0 11.1.1.8.0
Oracle Fusion Middleware Monitor (Apache Tomcat) 11.2.1.0.12 11.2.1.0.12
Oracle MySQL MySQL Enterprise Monitor 3.1.4.7895 and earlier, 3.2.1.1049 and earlier
Oracle Supply Chain Products Suite Install 6.1, 6.2, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7 6.1 · 6.2 · 6.3.0 · 6.3.1 · 6.3.2 · 6.3.3 · 6.3.4 · 6.3.5 · 6.3.6 · 6.3.7
Oracle Virtualization Apache Tomcat VDI prior to 3.5.3 3.5.3

☕ Maven Library Packages

Artifact coordinates and fix boundaries from OSV.dev
Package CoordinateIntroducedFixedLast affected
org.apache.tomcat:tomcat 9.0.0.M1 9.0.0.M2 unbounded
org.apache.tomcat:tomcat 8.0.0.RC1 8.0.32 unbounded
org.apache.tomcat:tomcat 7.0.0 7.0.70 unbounded
org.apache.tomcat:tomcat 6.0.0 6.0.46 unbounded

🖥️ Product CPEs & Version Ranges

4 product(s) over 108 version claims (uncapped)
SourceVendorProductSchemeAffected Versions
nvd apache tomcat generic 6.0.0 · 6.0.0:alpha · 6.0.1 · 6.0.1:alpha · 6.0.2 · 6.0.2:alpha · 6.0.2:beta · 6.0.4 · 6.0.4:alpha · 6.0.10 · 6.0.11 · 6.0.13 · 6.0.14 · 6.0.16 · 6.0.18 · 6.0.20 · 6.0.24 · 6.0.26 · 6.0.28 · 6.0.29 · 6.0.30 · 6.0.32 · 6.0.33 · 6.0.35 · 6.0.36 · 6.0.37 · 6.0.39 · 6.0.41 · 6.0.43 · 6.0.44 · 7.0.0:beta · 7.0.2:beta · 7.0.4:beta · 7.0.5:beta · 7.0.6 · 7.0.10 · 7.0.11 · 7.0.12 · 7.0.14 · 7.0.16 · 7.0.19 · 7.0.20 · 7.0.21 · 7.0.22 · 7.0.23 · 7.0.25 · 7.0.26 · 7.0.27 · 7.0.28 · 7.0.29 · 7.0.30 · 7.0.32 · 7.0.33 · 7.0.34 · 7.0.35 · 7.0.37 · 7.0.39 · 7.0.40 · 7.0.41 · 7.0.42 · 7.0.47 · 7.0.50 · 7.0.52 · 7.0.53 · 7.0.54 · 7.0.55 · 7.0.56 · 7.0.57 · 7.0.59 · 7.0.61 · 7.0.62 · 7.0.63 · 7.0.64 · 7.0.65 · 7.0.67 · 8.0.0:rc1 · 8.0.0:rc10 · 8.0.0:rc3 · 8.0.0:rc5 · 8.0.1 · 8.0.3 · 8.0.11 · 8.0.12 · 8.0.14 · 8.0.15 · 8.0.17 · 8.0.18 · 8.0.20 · 8.0.21 · 8.0.22 · 8.0.23 · 8.0.24 · 8.0.26 · 8.0.27 · 8.0.28 · 8.0.29 · 8.0.30 · 9.0.0:milestone1
nvd canonical ubuntu linux generic 12.04 · 14.04 · 15.10 · 16.04
nvd debian debian linux generic 7.0 · 8.0
osv org.apache.tomcat tomcat generic ≥ 6.0.0 and < 6.0.46 · ≥ 7.0.0 and < 7.0.70 · ≥ 8.0.0 and < 8.0.32 · ≥ 9.0.0 and < 9.0.0

Manual classification context

A reviewer manually classified this CVE. The retained record includes the labels and products below, but not the reviewer's reasoning.

## Manual Classification Context **Labels:** HTTP, INSTALL, MONITOR (APACHE TOMCAT), TLS, APACHE TOMCAT, MONITORING: GENERAL, SECURITY (APACHE TOMCAT) **Products:** VIRTUAL DESKTOP INFRASTRUCTURE, ORACLE VIRTUALIZATION, TOMCAT, ORACLE SUPPLY CHAIN PRODUCTS SUITE, MANAGEMENT PACK FOR ORACLE GOLDENGATE, ORACLE COMMUNICATIONS APPLICATIONS, ORACLE WEBCENTER SITES, MYSQL ENTERPRISE MONITOR, ORACLE TRANSPORTATION MANAGEMENT, ORACLE FUSION MIDDLEWARE, ORACLE COMMUNICATIONS POLICY MANAGEMENT, ORACLE MYSQL

References

URLTags
https://github.com/apache/tomcat/commit/50f1b1da794cd93b70ab5456d3c2c984408e1506 WEB
https://github.com/apache/tomcat/commit/79e8ad03404c131009811855f9a30d8d01c0c736 WEB
https://github.com/apache/tomcat/commit/824eb1d1ad922e7652ecf51adb2b9eebb5bb88b5 WEB
https://github.com/apache/tomcat/commit/e1b1002129fea4033329f6f619ba219527bbbd40 WEB
https://github.com/apache/tomcat/commit/f626da75fd59da82b14dee7b8cc46ad51eefdbe5 WEB
https://github.com/apache/tomcat/commit/ff1b659dc366a2ad47cd8f7e3544c796a1b15e46 WEB
https://github.com/apache/tomcat80/commit/2e5cc28052e84ba45196949ba602484221bbf33c WEB
https://github.com/apache/tomcat80/commit/5430f30c79383e4d2d87785468905fcb00bace58 WEB
https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb%40%3Cdev.tomcat.apache.org%3E WEB
https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb@%3Cdev.tomcat.apache.org%3E WEB

Timeline

Published 2016-02-25 Last modified 2026-06-17
Published2016-02-25By the CVE Program.
NVD record modified2026-06-17NVD's own last-modified date for this record.