PT-2011-2861 · Apache · Apache Tomcat

CVE-2011-1088

·

Publicado

2011-03-11

·

Atualizado

2023-02-13

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 7.0.0 through 7.0.10
Description The issue allows remote attackers to bypass intended access restrictions via HTTP requests to a web application because Apache Tomcat does not follow ServletSecurity annotations. This means some areas of the application may not have been protected as expected.
Recommendations For Apache Tomcat versions 7.0.0 through 7.0.10, update to version 7.0.11 to fully resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2011-1088
GHSA-MG4V-RF8P-GHQQ

Produtos afetados

Apache Tomcat