CVE-2004-1452
Last modified
CVE-2004-1452 is a vulnerability of currently unknown severity. Tomcat before 5.0.27-r3 in Gentoo Linux sets the default permissions on the init scripts as tomcat:tomcat, but executes the scripts with root privileges, which could allow local users in the tomcat group to execute arbitrary commands as root by modifying the scripts.. EPSS estimates a 0.44% chance of exploitation in the next 30 days.
Description
Tomcat before 5.0.27-r3 in Gentoo Linux sets the default permissions on the init scripts as tomcat:tomcat, but executes the scripts with root privileges, which could allow local users in the tomcat group to execute arbitrary commands as root by modifying the scripts.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gentoo | Linux | 0.5 |
| Gentoo | Linux | 0.7 |
| Gentoo | Linux | 1.1a |
| Gentoo | Linux | 1.2 |
| Gentoo | Linux | 1.4 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-1452?
How severe is CVE-2004-1452?
How do I fix CVE-2004-1452?
Are you affected by CVE-2004-1452?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
