CVE-2016-5425 describes a local privilege escalation vulnerability affecting Tomcat packages on Red Hat Enterprise Linux 7, Fedora, CentOS, and Oracle Linux. This flaw stems from weak permissions on the /usr/lib/tmpfiles.d/tomcat.conf file, allowing local users who are members of the tomcat group to gain root privileges. Rated with a CVSS score of 7.8 (High), the vulnerability has a low attack complexity and can lead to complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, exploit code is publicly available via Metasploit and ExploitDB, and it has garnered community discussion, indicating awareness among threat actors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:apache:tomcat:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.