AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2016-6796.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 7.5CVSS 3.1 · nvd@nist.gov
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSModifiedModified Oct 08, 2026

Disclosure summary

A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via manipulation of the configuration parameters for the JSP Servlet.

Source-reported weakness categories

NVD-CWE-noinfo

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

NIST National Vulnerability Database · NVD-CVE-2016-6796

Open original source · Updated Oct 08, 2026

Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.

VendorProduct / associationVersion / bounds
apachetomcat* {"versionStartIncluding":"8.5.0","versionEndIncluding":"8.5.4"}
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
debiandebian_linux8.0
netapponcommand_insight-
netapponcommand_shift-
netappsnap_creator_framework-
canonicalubuntu_linux16.04
oracletekelec_platform_distribution7.4.0
oracletekelec_platform_distribution7.7.1
redhatjboss_enterprise_application_platform6.4
redhatjboss_enterprise_web_server3.0.0
redhatenterprise_linux_desktop7.0
redhatenterprise_linux_eus7.4
redhatenterprise_linux_eus7.5
redhatenterprise_linux_eus7.6
redhatenterprise_linux_eus7.7
redhatenterprise_linux_server7.0
redhatenterprise_linux_server_aus7.4
redhatenterprise_linux_server_aus7.6
redhatenterprise_linux_server_aus7.7
redhatenterprise_linux_server_tus7.6
redhatenterprise_linux_server_tus7.7
redhatenterprise_linux_workstation7.0

Original records & references

PUBLISHED 2017-08-10T22:29:00-04:00
MODIFIED 2026-10-08T18:16:38-04:00
INGESTED 2026-10-10T20:50:18-04:00