Advertisement






Apache Tomcat 7.0.11 security constraint bypass

CVE Category Price Severity
CVE-2011-1088 CWE-XXXX $500 High
Author Risk Exploitation Type Date
ExploitMaster High Remote 2011-04-13
CPE
cpe:cpe:/a:apache:tomcat:7.0.11
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:M/Au:N/C:P/I:P/A:P 0.045 0.69929

CVSS vector description

Our sensors found this exploit at: http://cxsecurity.com/ascii/WLB-2011040174

Below is a copy:

Severity: Important

Vendor: The Apache Software Foundation

Versions Affected:
- Tomcat 7.0.11
- Earlier versions are not affected

Description:
A regression in the fix for CVE-2011-1088 meant that security
constraints were ignored when no login configuration was present in the
web.xml and the web application was marked as meta-data complete.

Mitigation:
Users of affected versions should apply one of the following mitigations:
- Upgrade to a Tomcat 7.0.12 or later
- Ensure a login configuration is defined in web.xml

Credit:
This issue was identified by the Apache Tomcat security team.

References:
http://tomcat.apache.org/security.html
http://tomcat.apache.org/security-7.html

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum