CVE-2016-0763 is a medium-severity vulnerability affecting Apache Tomcat versions 7.x, 8.x, and 9.x, as well as various Debian and Ubuntu distributions. It allows remote authenticated users to bypass SecurityManager restrictions due to improper authorization checks in the setGlobalContext method of ResourceLinkFactory. This flaw can lead to unauthorized reading or writing of application data, or cause a denial of service. The vulnerability has a CVSS score of 6.3, indicating a low attack complexity and requiring low privileges. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
7.0.0CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:7.0.0:beta:*:*:*:*:*:* | ||
7.0.2CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:7.0.2:beta:*:*:*:*:*:* | ||
7.0.4CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:7.0.4:beta:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.