VYPR
High severity7.5NVD Advisory· Published Aug 10, 2017· Updated Jun 17, 2026

CVE-2016-6797

CVE-2016-6797

Description

The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global JNDI resources to those resources explicitly linked to the web application. Therefore, it was possible for a web application to access any global JNDI resource whether an explicit ResourceLink had been configured or not.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.tomcat:tomcatMaven
>= 9.0.0.M1, < 9.0.0.M109.0.0.M10
org.apache.tomcat:tomcatMaven
>= 8.5.0, < 8.5.58.5.5
org.apache.tomcat:tomcatMaven
>= 8.0.0, < 8.0.378.0.37
org.apache.tomcat:tomcatMaven
>= 7.0.0, < 7.0.727.0.72

Affected products

43

Patches

Vulnerability mechanics

References

50

News mentions

0

No linked articles in our index yet.