Show plain JSON{"affected_release": [{"advisory": "RHSA-2017:0457", "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:3.1", "product_name": "Red Hat JBoss Web Server 3.1", "release_date": "2017-03-07T00:00:00Z"}, {"advisory": "RHSA-2017:0455", "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:3.1::el6", "package": "hibernate4-eap6-0:4.2.23-1.Final_redhat_1.1.ep6.el6", "product_name": "Red Hat JBoss Web Server 3 for RHEL 6", "release_date": "2017-03-07T00:00:00Z"}, {"advisory": "RHSA-2017:0455", "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:3.1::el6", "package": "jbcs-httpd24-0:1-3.jbcs.el6", "product_name": "Red Hat JBoss Web Server 3 for RHEL 6", "release_date": "2017-03-07T00:00:00Z"}, {"advisory": "RHSA-2017:0455", "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:3.1::el6", "package": "jbcs-httpd24-apache-commons-daemon-0:1.0.15-1.redhat_2.1.jbcs.el6", "product_name": "Red Hat JBoss Web Server 3 for RHEL 6", "release_date": "2017-03-07T00:00:00Z"}, {"advisory": "RHSA-2017:0455", "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:3.1::el6", "package": "jbcs-httpd24-apache-commons-daemon-jsvc-1:1.0.15-17.redhat_2.jbcs.el6", "product_name": "Red Hat JBoss Web Server 3 for RHEL 6", "release_date": "2017-03-07T00:00:00Z"}, {"advisory": "RHSA-2017:0455", "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:3.1::el6", "package": "mod_cluster-0:1.3.5-2.Final_redhat_2.1.ep7.el6", "product_name": "Red Hat JBoss Web Server 3 for RHEL 6", "release_date": "2017-03-07T00:00:00Z"}, {"advisory": "RHSA-2017:0455", "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:3.1::el6", "package": "tomcat7-0:7.0.70-16.ep7.el6", "product_name": "Red Hat JBoss Web Server 3 for RHEL 6", "release_date": "2017-03-07T00:00:00Z"}, {"advisory": "RHSA-2017:0455", "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:3.1::el6", "package": "tomcat8-0:8.0.36-17.ep7.el6", "product_name": "Red Hat JBoss Web Server 3 for RHEL 6", "release_date": "2017-03-07T00:00:00Z"}, {"advisory": "RHSA-2017:0455", "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:3.1::el6", "package": "tomcat-native-0:1.2.8-9.redhat_9.ep7.el6", "product_name": "Red Hat JBoss Web Server 3 for RHEL 6", "release_date": "2017-03-07T00:00:00Z"}, {"advisory": "RHSA-2017:0455", "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:3.1::el6", "package": "tomcat-vault-0:1.0.8-9.Final_redhat_2.1.ep7.el6", "product_name": "Red Hat JBoss Web Server 3 for RHEL 6", "release_date": "2017-03-07T00:00:00Z"}, {"advisory": "RHSA-2017:0456", "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:3.1::el7", "package": "hibernate4-eap6-0:4.2.23-1.Final_redhat_1.1.ep6.el7", "product_name": "Red Hat JBoss Web Server 3 for RHEL 7", "release_date": "2017-03-07T00:00:00Z"}, {"advisory": "RHSA-2017:0456", "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:3.1::el7", "package": "jbcs-httpd24-0:1-3.jbcs.el7", "product_name": "Red Hat JBoss Web Server 3 for RHEL 7", "release_date": "2017-03-07T00:00:00Z"}, {"advisory": "RHSA-2017:0456", "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:3.1::el7", "package": "jbcs-httpd24-apache-commons-daemon-0:1.0.15-1.redhat_2.1.jbcs.el7", "product_name": "Red Hat JBoss Web Server 3 for RHEL 7", "release_date": "2017-03-07T00:00:00Z"}, {"advisory": "RHSA-2017:0456", "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:3.1::el7", "package": "jbcs-httpd24-apache-commons-daemon-jsvc-1:1.0.15-17.redhat_2.jbcs.el7", "product_name": "Red Hat JBoss Web Server 3 for RHEL 7", "release_date": "2017-03-07T00:00:00Z"}, {"advisory": "RHSA-2017:0456", "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:3.1::el7", "package": "mod_cluster-0:1.3.5-2.Final_redhat_2.1.ep7.el7", "product_name": "Red Hat JBoss Web Server 3 for RHEL 7", "release_date": "2017-03-07T00:00:00Z"}, {"advisory": "RHSA-2017:0456", "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:3.1::el7", "package": "tomcat7-0:7.0.70-16.ep7.el7", "product_name": "Red Hat JBoss Web Server 3 for RHEL 7", "release_date": "2017-03-07T00:00:00Z"}, {"advisory": "RHSA-2017:0456", "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:3.1::el7", "package": "tomcat8-0:8.0.36-17.ep7.el7", "product_name": "Red Hat JBoss Web Server 3 for RHEL 7", "release_date": "2017-03-07T00:00:00Z"}, {"advisory": "RHSA-2017:0456", "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:3.1::el7", "package": "tomcat-native-0:1.2.8-9.redhat_9.ep7.el7", "product_name": "Red Hat JBoss Web Server 3 for RHEL 7", "release_date": "2017-03-07T00:00:00Z"}, {"advisory": "RHSA-2017:0456", "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:3.1::el7", "package": "tomcat-vault-0:1.0.8-9.Final_redhat_2.1.ep7.el7", "product_name": "Red Hat JBoss Web Server 3 for RHEL 7", "release_date": "2017-03-07T00:00:00Z"}], "bugzilla": {"description": "tomcat: unsafe chown of catalina.log in tomcat init script allows privilege escalation", "id": "1376712", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1376712"}, "csaw": false, "cvss": {"cvss_base_score": "6.9", "cvss_scoring_vector": "AV:L/AC:M/Au:N/C:C/I:C/A:C", "status": "verified"}, "cvss3": {"cvss3_base_score": "7.0", "cvss3_scoring_vector": "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "status": "verified"}, "cwe": "CWE-284", "details": ["The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debian jessie and the tomcat6 and libtomcat6-java packages before 6.0.35-1ubuntu3.8 on Ubuntu 12.04 LTS, the tomcat7 and libtomcat7-java packages before 7.0.52-1ubuntu0.7 on Ubuntu 14.04 LTS, and tomcat8 and libtomcat8-java packages before 8.0.32-1ubuntu1.2 on Ubuntu 16.04 LTS allows local users with access to the tomcat account to gain root privileges via a symlink attack on the Catalina log file, as demonstrated by /var/log/tomcat7/catalina.out.", "It was reported that the Tomcat init script performed unsafe file handling, which could result in local privilege escalation."], "name": "CVE-2016-1240", "package_state": [{"cpe": "cpe:/a:redhat:developer_toolset:3.1", "fix_state": "Not affected", "package_name": "devtoolset-3-tomcat", "product_name": "Red Hat Developer Toolset 3.1"}, {"cpe": "cpe:/o:redhat:enterprise_linux:5", "fix_state": "Not affected", "package_name": "tomcat5", "product_name": "Red Hat Enterprise Linux 5"}, {"cpe": "cpe:/o:redhat:enterprise_linux:6", "fix_state": "Not affected", "package_name": "tomcat6", "product_name": "Red Hat Enterprise Linux 6"}, {"cpe": "cpe:/o:redhat:enterprise_linux:7", "fix_state": "Not affected", "package_name": "tomcat", "product_name": "Red Hat Enterprise Linux 7"}, {"cpe": "cpe:/a:redhat:jboss_data_grid:6", "fix_state": "Not affected", "package_name": "jbossweb", "product_name": "Red Hat JBoss Data Grid 6"}, {"cpe": "cpe:/a:redhat:jboss_data_virtualization:6", "fix_state": "Not affected", "package_name": "jbossweb", "product_name": "Red Hat JBoss Data Virtualization 6"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:6", "fix_state": "Not affected", "package_name": "jbossweb", "product_name": "Red Hat JBoss Enterprise Application Platform 6"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7", "fix_state": "Not affected", "package_name": "Scripts", "product_name": "Red Hat JBoss Enterprise Application Platform 7"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_web_server:2", "fix_state": "Will not fix", "package_name": "tomcat6", "product_name": "Red Hat JBoss Enterprise Web Server 2"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_web_server:2", "fix_state": "Will not fix", "package_name": "tomcat7", "product_name": "Red Hat JBoss Enterprise Web Server 2"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_web_server:3", "fix_state": "Fix deferred", "package_name": "tomcat7", "product_name": "Red Hat JBoss Enterprise Web Server 3"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_web_server:3", "fix_state": "Fix deferred", "package_name": "tomcat8", "product_name": "Red Hat JBoss Enterprise Web Server 3"}, {"cpe": "cpe:/a:redhat:jboss_operations_network:3", "fix_state": "Not affected", "package_name": "jbossweb", "product_name": "Red Hat JBoss Operations Network 3"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_portal_platform:6", "fix_state": "Not affected", "package_name": "jbossweb", "product_name": "Red Hat JBoss Portal 6"}, {"cpe": "cpe:/a:redhat:rhel_software_collections:2", "fix_state": "Not affected", "package_name": "rh-java-common-tomcat", "product_name": "Red Hat Software Collections"}], "public_date": "2016-09-15T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2016-1240\nhttps://nvd.nist.gov/vuln/detail/CVE-2016-1240\nhttp://legalhackers.com/advisories/Tomcat-DebPkgs-Root-Privilege-Escalation-Exploit-CVE-2016-1240.txt"], "threat_severity": "Important"}