native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to an application.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Tomcat | — | Upgrade Apache Tomcat to 5.5.34Upgrade Apache Tomcat to 7.0.20Upgrade Apache Tomcat to 6.0.33Upgrade Apache Tomcat to the latest available version | May 17, 2012 | Aug 15, 2011 |
| Debian | — | Upgrade commons-daemon | Jul 30, 2024 | Aug 15, 2011 |
| Gentoo Linux | — | Upgrade www-servers/tomcat. | Oct 30, 2017 | Aug 15, 2011 |
| Hpux | — | Update hpuxws22TOMCAT.TOMCAT to the latest version | Aug 11, 2017 | Aug 15, 2011 |
| Suse | — | Upgrade apache-commons-daemon-javadocUpgrade apache-commons-daemonUpgrade apache-commons-daemon-jsvc | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libcommons-daemon-java | Nov 8, 2024 | Aug 15, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub