{
    "id": "CVE-2016-5018",
    "published": "2017-08-10 16:29:00",
    "last_modified": "2026-06-17 00:48:37",
    "cvss_score": "9.1",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
    "cwe": null,
    "description": "In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able to bypass a configured SecurityManager via a Tomcat utility method that was accessible to web applications.",
    "epss_score": "0.10303",
    "epss_percentile": "0.95574",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 0,
    "updated_at": "2026-10-03 18:17:16",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "EPSS 10.3% — above the 10% action threshold."
    },
    "products": [
        {
            "vendor": "apache",
            "product": "tomcat"
        },
        {
            "vendor": "canonical",
            "product": "ubuntu_linux"
        },
        {
            "vendor": "debian",
            "product": "debian_linux"
        },
        {
            "vendor": "netapp",
            "product": "oncommand_insight"
        },
        {
            "vendor": "netapp",
            "product": "oncommand_shift"
        },
        {
            "vendor": "netapp",
            "product": "snap_creator_framework"
        },
        {
            "vendor": "oracle",
            "product": "tekelec_platform_distribution"
        },
        {
            "vendor": "redhat",
            "product": "enterprise_linux_desktop"
        },
        {
            "vendor": "redhat",
            "product": "enterprise_linux_eus"
        },
        {
            "vendor": "redhat",
            "product": "enterprise_linux_server"
        },
        {
            "vendor": "redhat",
            "product": "enterprise_linux_server_aus"
        },
        {
            "vendor": "redhat",
            "product": "enterprise_linux_server_tus"
        },
        {
            "vendor": "redhat",
            "product": "enterprise_linux_workstation"
        },
        {
            "vendor": "redhat",
            "product": "jboss_enterprise_application_platform"
        },
        {
            "vendor": "redhat",
            "product": "jboss_enterprise_web_server"
        }
    ],
    "kev_detail": null,
    "exploits": [],
    "refs_list": [
        "http://packetstormsecurity.com/files/155873/Tomcat-9.0.0.M1-Sandbox-Escape.html",
        "http://rhn.redhat.com/errata/RHSA-2017-0457.html",
        "http://rhn.redhat.com/errata/RHSA-2017-1551.html",
        "http://www.debian.org/security/2016/dsa-3720",
        "http://www.securityfocus.com/bid/93942",
        "http://www.securitytracker.com/id/1037142",
        "http://www.securitytracker.com/id/1038757",
        "https://access.redhat.com/errata/RHSA-2017:0455",
        "https://access.redhat.com/errata/RHSA-2017:0456",
        "https://access.redhat.com/errata/RHSA-2017:1548",
        "https://access.redhat.com/errata/RHSA-2017:1549",
        "https://access.redhat.com/errata/RHSA-2017:1550",
        "https://access.redhat.com/errata/RHSA-2017:1552",
        "https://access.redhat.com/errata/RHSA-2017:2247",
        "https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3E",
        "https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113%40%3Cdev.tomcat.apache.org%3E",
        "https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3E",
        "https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b%40%3Cdev.tomcat.apache.org%3E",
        "https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3E",
        "https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424%40%3Cdev.tomcat.apache.org%3E",
        "https://lists.apache.org/thread.html/9b3a63a20c87179815fdea14f6766853bafe79a0042dc0b4aa878a9e%40%3Cannounce.tomcat.apache.org%3E",
        "https://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc%40%3Cdev.tomcat.apache.org%3E",
        "https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95%40%3Cdev.tomcat.apache.org%3E",
        "https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb%40%3Cdev.tomcat.apache.org%3E",
        "https://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c%40%3Cdev.tomcat.apache.org%3E"
    ]
}