Vulnerability Bulletins

DSA-3447 tomcat7 - security update

   
Affected software Debian
 
It was discovered that malicious web applications could use theExpression Language to bypass protections of a Security Manager asexpressions were evaluated within a privileged code section.

More info:

https://www.debian.org/security/2016/dsa-3447