The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a vigilance database and tools to fix them.

Vulnerability of Apache Tomcat: code execution via PersistentManager

Synthesis of the vulnerability 

An attacker, who is allowed to upload a malicious web application on the service, can use the PersistentManager of Apache Tomcat, in order to run code.
Vulnerable systems: Tomcat, Debian, BIG-IP Hardware, TMOS, HP-UX, QRadar SIEM, Snap Creator Framework, openSUSE Leap, Oracle Communications, Oracle Directory Server, Oracle Directory Services Plus, Oracle Fusion Middleware, Oracle GlassFish Server, Oracle Identity Management, Oracle iPlanet Web Server, Oracle OIT, Oracle Virtual Directory, WebLogic, Oracle Web Tier, RHEL, SUSE Linux Enterprise Desktop, SLES, Ubuntu.
Severity of this threat: 2/4.
Creation date: 22/02/2016.
Références of this weakness: 1980693, 1983989, c05054964, c05150442, cpuapr2017, cpujul2018, cpuoct2017, CVE-2016-0714, DSA-3530-1, DSA-3552-1, DSA-3609-1, HPSBUX03561, HPSBUX03606, K30971148, NTAP-20180531-0001, openSUSE-SU-2016:0865-1, RHSA-2016:1087-01, RHSA-2016:1088-01, RHSA-2016:1089-01, RHSA-2016:2045-01, RHSA-2016:2599-02, RHSA-2016:2807-01, RHSA-2016:2808-01, SOL30971148, SUSE-SU-2016:0769-1, SUSE-SU-2016:0822-1, SUSE-SU-2016:0839-1, USN-3024-1, VIGILANCE-VUL-18998.

Description of the vulnerability 

The Apache Tomcat product can execute a web application from an untrusted source with a Security Manager.

However, a malicious application can use PersistentManager to store an object in a session, and thus execute code.

An attacker, who is allowed to upload a malicious web application on the service, can therefore use the PersistentManager of Apache Tomcat, in order to run code.
Full bulletin, software filtering, emails, fixes, ... (Request your free trial)

This computer vulnerability announce impacts software or systems such as Tomcat, Debian, BIG-IP Hardware, TMOS, HP-UX, QRadar SIEM, Snap Creator Framework, openSUSE Leap, Oracle Communications, Oracle Directory Server, Oracle Directory Services Plus, Oracle Fusion Middleware, Oracle GlassFish Server, Oracle Identity Management, Oracle iPlanet Web Server, Oracle OIT, Oracle Virtual Directory, WebLogic, Oracle Web Tier, RHEL, SUSE Linux Enterprise Desktop, SLES, Ubuntu.

Our Vigil@nce team determined that the severity of this cybersecurity bulletin is medium.

The trust level is of type confirmed by the editor, with an origin of document.

An attacker with a expert ability can exploit this threat alert.

Solutions for this threat 

Apache Tomcat: version 8.0.32.
The version 8.0.32 is fixed:
  http://tomcat.apache.org/download-80.cgi

Apache Tomcat: version 7.0.68.
The version 7.0.68 is fixed:
  http://tomcat.apache.org/download-70.cgi

Apache Tomcat: version 6.0.45.
The version 6.0.45 is fixed:
  http://tomcat.apache.org/download-60.cgi

Debian: new tomcat6 packages.
New packages are available:
  Debian 7: tomcat6 6.0.45+dfsg-1~deb7u1

Debian: new tomcat7 packages.
New packages are available:
  Debian 7: tomcat7 7.0.28-4+deb7u4
  Debian 8: tomcat7 7.0.56-3+deb8u2

Debian: new tomcat8 packages.
New packages are available:
  Debian 8: tomcat8 8.0.14-1+deb8u2

F5 BIG-IP: solution for Tomcat 6.
The solution is indicated in information sources.

HP-UX: Tomcat version 6.0.45.01.
Tomcat version 6.0.45.01 is fixed:
  https://h20392.www2.hpe.com/portal/swdepot/displayProductInfo.do?productNumber=HPUXWSATW407

HP-UX: version D.7.0.68.01.
The version D.7.0.68.01 is fixed:
  https://h20392.www2.hpe.com/portal/swdepot/displayProductInfo.do?productNumber=HPUXWST706801

IBM QRadar SIEM: patch for Tomcat.
A patch is indicated in information sources.

IBM TADDM: patch for Tomcat.
A patch is indicated in information sources.

NetApp Snap Creator Framework: patch for Tomcat.
A patch is available:
  https://mysupport.netapp.com/NOW/download/software/snapcreator_framework/4.3P1/

openSUSE Leap 42.1: new tomcat packages.
New packages are available:
  openSUSE Leap 42.1: tomcat 8.0.32-5.1

Oracle Communications: CPU of July 2018.
A Critical Patch Update is available:
  https://support.oracle.com/rs?type=doc&id=2410237.1
  https://support.oracle.com/rs?type=doc&id=2406191.1
  https://support.oracle.com/rs?type=doc&id=2410234.1
  https://support.oracle.com/rs?type=doc&id=2408211.1
  https://support.oracle.com/rs?type=doc&id=2406689.1
  https://support.oracle.com/rs?type=doc&id=2408212.1
  https://support.oracle.com/rs?type=doc&id=2410243.1
  https://support.oracle.com/rs?type=doc&id=2410198.1

Oracle Fusion Middleware: CPU of April 2017.
A Critical Patch Update is available:
  https://support.oracle.com/rs?type=doc&id=2228898.1

Oracle Fusion Middleware: CPU of October 2017.
A Critical Patch Update is available:
  https://support.oracle.com/rs?type=doc&id=2296870.1

Red Hat JBoss Web Server: version 2.1.2.
The version 2.1.2 is fixed:
  https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=webserver&downloadType=distributions&version=2.1.2

Red Hat JBoss Web Server: version 3.0.3.
The version 3.0.3 is fixed.

RHEL 6.8: new tomcat6 packages.
New packages are available:
  RHEL 6: tomcat6 6.0.24-98.el6_8

RHEL 7: new tomcat packages.
New packages are available:
  RHEL 7: tomcat 7.0.69-10.el7

SUSE LE 11: new tomcat6 packages.
New packages are available:
  SUSE LE 11 SP4: tomcat6 6.0.45-0.50.1

SUSE LE 12: new tomcat packages.
New packages are available:
  SUSE LE 12 RTM: tomcat 7.0.68-7.6.1
  SUSE LE 12 SP1: tomcat 8.0.32-3.1

Ubuntu: new tomcat packages.
New packages are available:
  Ubuntu 16.04 LTS: libtomcat7-java 7.0.68-1ubuntu0.1
  Ubuntu 15.10: libtomcat7-java 7.0.64-1ubuntu0.3
  Ubuntu 14.04 LTS: libtomcat7-java 7.0.52-1ubuntu0.6
  Ubuntu 12.04 LTS: libtomcat6-java 6.0.35-1ubuntu3.7
Full bulletin, software filtering, emails, fixes, ... (Request your free trial)

Computer vulnerabilities tracking service 

Vigil@nce provides a networks vulnerabilities database. The Vigil@nce vulnerability database contains several thousand vulnerabilities.