Beveiligingsadvies

CVE-2011-3376

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2011-11-11 21:00:00
Laatst bijgewerkt 2024-08-06 23:29:56
Toegewezen door redhat
CVSS-score geen score
Status PUBLISHED

Beschrijving

org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local users to gain privileges by using an untrusted web application to access the Manager application's functionality.