CVE-2011-3376
org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local users to gain privileges by using an untrusted web application to access…
Does this matter?
Lower severity and a low EPSS score (0.64%). Track it; it rarely justifies an emergency change on its own.
Description
org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local users to gain privileges by using an untrusted web application to access the Manager application's functionality.
- CVSS 2.0
- 4.4 MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 0.64% probability · 49th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- apache/tomcat
- Source
- secalert@redhat.com
References
- http://svn.apache.org/viewvc/tomcat/tc7.0.x/trunk/java/org/apache/catalina/core/DefaultInstanceManager.java?r1=1176588&r2=1176587&pathrev=1176588Patch
- http://svn.apache.org/viewvc?view=revision&revision=1176588
- http://tomcat.apache.org/security-7.htmlVendor Advisory
- http://www.securityfocus.com/bid/50603
- http://svn.apache.org/viewvc/tomcat/tc7.0.x/trunk/java/org/apache/catalina/core/DefaultInstanceManager.java?r1=1176588&r2=1176587&pathrev=1176588Patch
- http://svn.apache.org/viewvc?view=revision&revision=1176588
- http://tomcat.apache.org/security-7.htmlVendor Advisory
- http://www.securityfocus.com/bid/50603
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.