Description
While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use the appropriate facade object. When running an untrusted application under a SecurityManager, it was therefore possible for that untrusted application to retain a reference to the request or response object and thereby access and/or modify information associated with another web application.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-924-1 | tomcat7 security update |
Debian DSA |
DSA-3842-1 | tomcat7 security update |
Debian DSA |
DSA-3843-1 | tomcat8 security update |
EUVD |
EUVD-2022-2247 | While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use the appropriate facade object. When running an untrusted application under a SecurityManager, it was therefore possible for that untrusted application to retain a reference to the request or response object and thereby access and/or modify information associated with another web application. |
Github GHSA |
GHSA-3vx3-xf6q-r5xp | Exposure of Resource to Wrong Sphere in Apache Tomcat |
Ubuntu USN |
USN-3519-1 | Tomcat vulnerabilities |
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-05T15:11:48.389Z
Reserved: 2017-01-29T00:00:00.000Z
Link: CVE-2017-5648
No data.
Status : Modified
Published: 2017-04-17T16:59:00.367
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-5648
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN