Apache Tomcat CVE-2017-5648 Information Disclosure Vulnerability

description-logoDescription

While investigating bug 60718, it was noticed that some calls to application listeners did not use the appropriate facade object. When running an untrusted application under a SecurityManager, it was therefore possible for that untrusted application to retain a reference to the request or response object and thereby access and/or modify information associated with another web application.

affected-products-logoAffected Applications

Apache Tomcat

CVE References

CVE-2017-5648