vulnerability

Ubuntu: (Multiple Advisories) (CVE-2016-1240): Tomcat vulnerability

Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
Oct 3, 2016
Added
Oct 3, 2016
Modified
Aug 18, 2025

Description

Dawid Golunski discovered that the Tomcat init script incorrectly handled
creating log files. A remote attacker could possibly use this issue to
obtain root privileges. (CVE-2016-1240)

This update also reverts a change in behaviour introduced in USN-3024-1 by
setting mapperContextRootRedirectEnabled to True by default.

Solutions

ubuntu-upgrade-libservlet2-5-javaubuntu-upgrade-libtomcat6-javaubuntu-upgrade-libtomcat7-javaubuntu-upgrade-libtomcat8-javaubuntu-upgrade-tomcat6ubuntu-upgrade-tomcat7ubuntu-upgrade-tomcat8
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.