suse · CVE-2016-6794

Quick triage

Priority: low Published: 2021-05-30 13:45:00 UTC Updated: 2025-10-05 02:40:20 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2016-6794 severity low: SUSE including 72 source package names (tomcat-7.0.76-2.el7, tomcat-7.0.78-7.13.4, …), 166 product×package rows across 19 product lines (SUSE Liberty Linux 7, SUSE Linux Enterprise High Performance Computing 12 SP5, … (19 product lines)): Fixed 166.

Description:

When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, 6.0.0 to 6.0.45 the system property replacement feature for configuration files could be used by a malicious web application to bypass the SecurityManager and read system properties that should not be visible.

cvelogic Threat Intelligence