peter bassill · operator
$ cve CVE-2016-5018 JSON

CVE-2016-5018

9.1
CRITICAL · CVSS 3.1 · EPSS 10.3% (pctl 96)

Patch early

EPSS 10.3% — above the 10% action threshold.

Description

In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able to bypass a configured SecurityManager via a Tomcat utility method that was accessible to web applications.

Scoring

CVSS9.1 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS10.3% — more likely to be exploited than 96% of all CVEs
On CISA KEVno
Public exploitnone known
Published2017-08-10
Last modified2026-06-17

Affected (15)

VendorProduct
apachetomcat
canonicalubuntu linux
debiandebian linux
netapponcommand insight
netapponcommand shift
netappsnap creator framework
oracletekelec platform distribution
redhatenterprise linux desktop
redhatenterprise linux eus
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server tus
redhatenterprise linux workstation
redhatjboss enterprise application platform
redhatjboss enterprise web server

References

→ the Explorer  ·  watch your stack  ·  NVD