The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 uses weak permissions for (1) /etc/sysconfig/tomcat and (2) /etc/tomcat/tomcat.conf, which allows local users to gain privileges by leveraging membership in the tomcat group.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/93478 | vdb entry |
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.html | |
http://rhn.redhat.com/errata/RHSA-2016-2045.html | vendor advisory |
http://rhn.redhat.com/errata/RHSA-2016-2046.html | vendor advisory |
http://rhn.redhat.com/errata/RHSA-2017-0457.html | vendor advisory |
https://access.redhat.com/errata/RHSA-2017:0455 | vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1367447 | issue tracking vdb entry vendor advisory |
https://access.redhat.com/errata/RHSA-2017:0456 | vendor advisory |