{"id":"CGA-33f9-rvrh-3w3g","modified":"2026-09-07T01:20:33.959035911Z","published":"2025-10-30T20:13:19Z","upstream":["CVE-2016-5425","GHSA-c7fc-mp9g-99j3"],"references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/6b414817c2b0bf351138911c8c922ec5dd577ebc0b9a7f42d705752d%40%3Cissues.activemq.apache.org%3E"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2016-2046.html"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2016/10/10/2"},{"type":"ADVISORY","url":"http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.html"},{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1036979"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/93472"},{"type":"ADVISORY","url":"https://www.exploit-db.com/exploits/40488/"},{"type":"ADVISORY","url":"https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"},{"type":"EVIDENCE","url":"http://legalhackers.com/advisories/Tomcat-RedHat-Pkgs-Root-PrivEsc-Exploit-CVE-2016-5425.html"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/139041/Apache-Tomcat-8-7-6-Privilege-Escalation.html"}],"affected":[{"package":{"name":"tomcat-8.5.87","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/tomcat-8.5.87?arch=aarch64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0"}]}],"ecosystem_specific":{"components":[{"component_purl":"pkg:apk/tomcat-8.5.87","latest_event_status":"false_positive_determination","latest_event_timestamp":"2023-08-11T23:04:39Z","component_name":"tomcat-8.5.87","component_version":"","component_type":"apk","component_location":"/.PKGINFO"}]},"database_specific":{"source":"https://advisories.cgr.dev/chainguard/v3/osv/CGA-33f9-rvrh-3w3g.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}