CVE-2016-0714: Apache Tomcat

High severity, CVSS 8.8. EPSS: 13.1% chance of exploitation in the next 30 days.

The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 mishandles session attributes, which allows remote authenticated users to bypass intended SecurityManager restrictions and execute arbitrary code in a privileged context via a web application that places a crafted object in a session.

Affected products

  • Apache Tomcat: version 6.0.0 only; version 6.0.1 only; version 6.0.2 only; version 6.0.4 only; version 6.0.10 only; version 6.0.11 only; …
  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only; version 16.04 only
  • Debian Debian Linux: version 7.0 only; version 8.0 only

Published 2016-02-25. Last modified 2026-06-17.