CVE-2011-1419

EPSS 16.1%

Apache Tomcat does not follow ServletSecurity annotations

發布日:2022/5/17修改日:2024/1/19

描述

Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088.

受影響套件(1)

參考連結(13)