CVE advisoryCRITICAL
CVE-2016-5018
Apache Tomcat Security Manager Bypass Vulnerability.
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A vulnerability in Apache Tomcat allows a deployed malicious web application to bypass configured SecurityManager controls. This bypass occurs via an accessible Tomcat utility method, potentially enabling unauthorized actions or access if the web application is reachable. You should care because it affects a common web