CVE-2016-5425: Apache Tomcat

High severity, CVSS 7.8. EPSS: 3.8% chance of exploitation in the next 30 days.

The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain root privileges by leveraging membership in the tomcat group.

Affected products

  • Apache Tomcat: affected versions not specified

Published 2016-10-13. Last modified 2026-06-17.