PT-2011-3236 · Apache+1 · Apache Tomcat+2

CVE-2011-1582

·

Publicado

2011-05-12

·

Atualizado

2023-02-13

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security constraints that have been configured through annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088, CVE-2011-1183, and CVE-2011-1419.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-1582
GHSA-3XPJ-JGV5-Q4VV

Produtos afetados

Apache Tomcat
Apache Tomcat New
Org.Apache.Tomcat:Tomcat