CVE-2016-5425
The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain root privileges by leveraging membership in the tomcat group.
- Affected products
- Apache Tomcat, Centos, Red Hat
- Apache Tomcat
- All versions
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 3.8% (89th percentile)
- Weakness
- CWE-276
- NVD status
- Modified
- Published
- 2016-10-13
CVE-2016-5425 at NVD
7 known exploits for CVE-2016-5425
Proof-of-concept code and exploit modules indexed by Sploitus
Apache Tomcat Privilege Escalation Exploit
Apache Tomcat Privilege Escalation
Apache Tomcat 8/7/6 (RedHat-Based Distros) - Privilege Escalation
Apache Tomcat 876 (RedHat Based Distros) - Local Privilege Escalation
Apache Tomcat 8/7/6 (RedHat Based Distros) - Local Privilege Escalation
Apache Tomcat 8 / 7 / 6 Privilege Escalation
Apache Tomcat on RedHat Based Systems Insecure Temp Config Privilege Escalation