CVE-2014-7810
Publication date 7 June 2015
Last updated 24 July 2024
Ubuntu priority
The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypass a SecurityManager protection mechanism via a web application that leverages use of incorrect privileges during EL evaluation.
From the Ubuntu Security Team
It was discovered that the Tomcat Expression Language (EL) implementation incorrectly handled accessible interfaces implemented by inaccessible classes. An attacker could possibly use this issue to bypass a SecurityManager protection mechanism.
Status
Package | Ubuntu Release | Status |
---|---|---|
tomcat6 | 18.04 LTS bionic | Not in release |
16.04 LTS xenial |
Fixed 6.0.45+dfsg-1
|
|
14.04 LTS trusty |
Fixed 6.0.39-1ubuntu0.1
|
|
tomcat7 | 18.04 LTS bionic |
Not affected
|
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Fixed 7.0.52-1ubuntu0.3
|
|
tomcat8 | 18.04 LTS bionic |
Not affected
|
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Not in release | |
Patch details
Package | Patch details |
---|---|
tomcat6 | |
tomcat7 |
References
Related Ubuntu Security Notices (USN)
- USN-2655-1
- Tomcat vulnerabilities
- 25 June 2015
- USN-2654-1
- Tomcat vulnerabilities
- 25 June 2015