CVE-2016-6797

Source
https://cve.org/CVERecord?id=CVE-2016-6797
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-6797.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2016-6797
Aliases
Downstream
Related
Published
2017-08-10T22:29:00.203Z
Modified
2026-02-24T11:11:56.050991Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global JNDI resources to those resources explicitly linked to the web application. Therefore, it was possible for a web application to access any global JNDI resource whether an explicit ResourceLink had been configured or not.

References

Affected packages

Git / github.com/libical/libical

Affected ranges

Type
GIT
Repo
https://github.com/libical/libical
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

v1.*
v1.0.1
v2.*
v2.0.0
v3.*
v3.0.0

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-6797.json"