High severity7.8NVD Advisory· Published Oct 13, 2016· Updated May 6, 2026
CVE-2016-6325
CVE-2016-6325
Description
The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 uses weak permissions for (1) /etc/sysconfig/tomcat and (2) /etc/tomcat/tomcat.conf, which allows local users to gain privileges by leveraging membership in the tomcat group.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- rhn.redhat.com/errata/RHSA-2016-2045.htmlnvdVendor Advisory
- rhn.redhat.com/errata/RHSA-2016-2046.htmlnvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVDB EntryVendor Advisory
- rhn.redhat.com/errata/RHSA-2017-0457.htmlnvd
- www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.htmlnvd
- www.securityfocus.com/bid/93478nvd
- access.redhat.com/errata/RHSA-2017:0455nvd
- access.redhat.com/errata/RHSA-2017:0456nvd
News mentions
0No linked articles in our index yet.