{"id":"CVE-2016-6796","description":"A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via manipulation of the configuration parameters for the JSP Servlet.","cvssScore":7.5,"cvssVersion":"3.1","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","cvssMetrics":[{"version":"3.1","score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"},{"version":"2.0","score":5,"vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"}],"resolved":"NO-EXPLOIT-PUBLISHED","published":"2017-08-11","lastModified":"2026-06-17","affectedProducts":[{"vendor":"apache","product":"tomcat","versionStart":"\u003e=6.0.0","versionEnd":"\u003c=6.0.45"},{"vendor":"apache","product":"tomcat","versionStart":"\u003e=7.0.0","versionEnd":"\u003c=7.0.70"},{"vendor":"apache","product":"tomcat","versionStart":"\u003e=8.0","versionEnd":"\u003c=8.0.36"},{"vendor":"apache","product":"tomcat","versionStart":"\u003e=8.5.0","versionEnd":"\u003c=8.5.4"},{"vendor":"apache","product":"tomcat","version":"9.0.0","update":"milestone1"},{"vendor":"apache","product":"tomcat","version":"9.0.0","update":"milestone2"},{"vendor":"apache","product":"tomcat","version":"9.0.0","update":"milestone3"},{"vendor":"apache","product":"tomcat","version":"9.0.0","update":"milestone4"},{"vendor":"apache","product":"tomcat","version":"9.0.0","update":"milestone5"},{"vendor":"apache","product":"tomcat","version":"9.0.0","update":"milestone6"},{"vendor":"apache","product":"tomcat","version":"9.0.0","update":"milestone7"},{"vendor":"apache","product":"tomcat","version":"9.0.0","update":"milestone8"},{"vendor":"apache","product":"tomcat","version":"9.0.0","update":"milestone9"},{"vendor":"debian","product":"debian linux","version":"8.0"},{"vendor":"netapp","product":"oncommand insight"},{"vendor":"netapp","product":"oncommand shift"},{"vendor":"netapp","product":"snap creator framework"},{"vendor":"canonical","product":"ubuntu linux","version":"16.04"},{"vendor":"oracle","product":"tekelec platform distribution","version":"7.4.0"},{"vendor":"oracle","product":"tekelec platform distribution","version":"7.7.1"}],"totalAffectedProducts":15,"references":[{"url":"https://github.com/apache/tomcat/commit/f603f2f4595073f9490e01699d2083112a7c09a7","source":"osv","tags":["WEB"]},{"url":"https://github.com/apache/tomcat/commit/f97769f50ee2613e1bf27107a01d48907fd993ac","source":"osv","tags":["WEB"]},{"url":"https://github.com/apache/tomcat/commit/ffa0346fba2946401630291b642f1cff66d6a2be","source":"osv","tags":["WEB"]},{"url":"https://github.com/apache/tomcat80/commit/d98fa92b9dfc90fe1ffdaa3cce1be3be84532260","source":"osv","tags":["WEB"]},{"url":"https://access.redhat.com/errata/RHSA-2017:0455","source":"osv","tags":["WEB"]},{"url":"https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424@%3Cdev.tomcat.apache.org%3E","source":"osv","tags":["WEB"]},{"url":"https://lists.apache.org/thread.html/88855876c33f2f9c532ffb75bfee570ccf0b17ffa77493745af9a17a%40%3Cdev.tomcat.apache.org%3E","source":"osv","tags":["WEB"]},{"url":"https://lists.apache.org/thread.html/88855876c33f2f9c532ffb75bfee570ccf0b17ffa77493745af9a17a@%3Cdev.tomcat.apache.org%3E","source":"osv","tags":["WEB"]},{"url":"https://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc%40%3Cdev.tomcat.apache.org%3E","source":"osv","tags":["WEB"]},{"url":"https://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc@%3Cdev.tomcat.apache.org%3E","source":"osv","tags":["WEB"]}],"reasoning":{"decidingSource":"no-exploit-published","decidingReason":"This CVE is not listed in CISA KEV, CISA Vulnrichment records no active exploitation, and no reviewed exploit catalogue carries an entry for it. Nobody has published something a stranger can run, so it is not a candidate for a rule ahead of the ones where somebody has; an upstream fix path does exist, so the remediation half of the candidacy still holds. This is a statement about what has been published, not about whether the defect is reachable or serious.","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"no-match"},{"rule":"h2-history","stage":"scope","outcome":"no-match"},{"rule":"non-java-upstream","stage":"scope","outcome":"no-match"},{"rule":"oracle-component","stage":"scope","outcome":"no-match"},{"rule":"osv-maven","stage":"scope","outcome":"matched","status":"QUEUED-FOR-REVIEW","detail":"Maven packages: org.apache.tomcat:tomcat"},{"rule":"patch-hint","stage":"disposition","outcome":"no-match"},{"rule":"open-source-maven","stage":"disposition","outcome":"matched","status":"MITIGATION-CANDIDATE","detail":"Open-source Maven artifact indexed by OSV (Maven packages: org.apache.tomcat:tomcat). The source is public, which makes an ARMR patch rule a candidate; nothing here establishes that one can be written."},{"rule":"poc-derivable","stage":"disposition","outcome":"skipped"},{"rule":"no-exploit","stage":"disposition","outcome":"skipped"},{"rule":"secure-rule-match","stage":"disposition","outcome":"no-match"},{"rule":"below-action-threshold","stage":"disposition","outcome":"no-match","detail":"Severity is HIGH — only MEDIUM/LOW are deprioritized"},{"rule":"no-exploit-published","stage":"disposition","outcome":"matched","status":"NO-EXPLOIT-PUBLISHED","detail":"No working exploit has been published, and an upstream fix path does exist, so the remediation half of the candidacy still holds.","decisive":true}],"affectedProducts":[{"vendor":"apache","product":"tomcat","isKnown":true,"cpe":"cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*","source":"yaml"},{"vendor":"debian","product":"debian_linux","isKnown":false,"cpe":"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"},{"vendor":"netapp","product":"oncommand_insight","isKnown":false,"cpe":"cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*"},{"vendor":"netapp","product":"oncommand_shift","isKnown":false,"cpe":"cpe:2.3:a:netapp:oncommand_shift:-:*:*:*:*:*:*:*"},{"vendor":"netapp","product":"snap_creator_framework","isKnown":false,"cpe":"cpe:2.3:a:netapp:snap_creator_framework:-:*:*:*:*:*:*:*"},{"vendor":"canonical","product":"ubuntu_linux","isKnown":false,"cpe":"cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*"},{"vendor":"oracle","product":"tekelec_platform_distribution","isKnown":false,"cpe":"cpe:2.3:a:oracle:tekelec_platform_distribution:7.4.0:*:*:*:*:*:*:*"},{"vendor":"redhat","product":"jboss_enterprise_application_platform","isKnown":true,"cpe":"cpe:2.3:a:redhat:jboss_enterprise_application_platform:6.4:*:*:*:*:*:*:*","source":"yaml"},{"vendor":"redhat","product":"jboss_enterprise_web_server","isKnown":true,"cpe":"cpe:2.3:a:redhat:jboss_enterprise_web_server:3.0.0:*:*:*:*:*:*:*","source":"yaml"},{"vendor":"redhat","product":"enterprise_linux_desktop","isKnown":false,"cpe":"cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*"},{"vendor":"redhat","product":"enterprise_linux_eus","isKnown":false,"cpe":"cpe:2.3:o:redhat:enterprise_linux_eus:7.4:*:*:*:*:*:*:*"},{"vendor":"redhat","product":"enterprise_linux_server","isKnown":false,"cpe":"cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*"},{"vendor":"redhat","product":"enterprise_linux_server_aus","isKnown":false,"cpe":"cpe:2.3:o:redhat:enterprise_linux_server_aus:7.4:*:*:*:*:*:*:*"},{"vendor":"redhat","product":"enterprise_linux_server_tus","isKnown":false,"cpe":"cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6:*:*:*:*:*:*:*"},{"vendor":"redhat","product":"enterprise_linux_workstation","isKnown":false,"cpe":"cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*"}],"affectedPackages":[{"name":"org.apache.tomcat:tomcat","introduced":"9.0.0.M1","fixed":"9.0.0.M10"},{"name":"org.apache.tomcat:tomcat","introduced":"8.5.0","fixed":"8.5.5"},{"name":"org.apache.tomcat:tomcat","introduced":"8.0.0.RC1","fixed":"8.0.37"},{"name":"org.apache.tomcat:tomcat","introduced":"7.0.0","fixed":"7.0.71"},{"name":"org.apache.tomcat:tomcat","introduced":"6.0.0","fixed":"6.0.46"}]},"assessment":{"record":{"state":"active"},"protection":{"level":"none"},"action":{"state":"unverified","type":"patch-rule"},"review":{"state":"automated","basis":"upstream-data"}},"signals":{"hasPOC":false,"pocCount":0},"kev":{"inKEV":false},"epss":{"available":true,"score":0.08321,"percentile":0.94628},"ssvc":{"available":false}}