CVE-2016-0763: Apache Tomcat

Medium severity, CVSS 6.3. EPSS: 11.3% chance of exploitation in the next 30 days.

The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLinkFactory.setGlobalContext callers are authorized, which allows remote authenticated users to bypass intended SecurityManager restrictions and read or write to arbitrary application data, or cause a denial of service (application disruption), via a web application that sets a crafted global context.

Affected products

  • Apache Tomcat: version 7.0.0 only; version 7.0.2 only; version 7.0.4 only; version 7.0.5 only; version 7.0.6 only; version 7.0.10 only; …
  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only; version 16.04 only
  • Debian Debian Linux: version 7.0 only; version 8.0 only

Published 2016-02-25. Last modified 2026-06-17.