← back
CVE-2016-5425

CVE-2016-5425

38Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 3.8%
from disclosure to weapon0 days
Published on NVDOct 13
1st PoCOct 10
metasploitOct 10
exploitation probability
3.8%top 11% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain root privileges by leveraging membership in the tomcat group.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.