CVE-2010-3718: Path Traversal
Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3718?
CVE-2010-3718 has a moderate severity level due to the risk of unauthorized file access and manipulation by local web applications.
How do I fix CVE-2010-3718?
To fix CVE-2010-3718, upgrade Apache Tomcat to version 5.5.30, 6.0.30, or 7.0.4 or later.
What versions of Apache Tomcat are affected by CVE-2010-3718?
CVE-2010-3718 affects Apache Tomcat versions 7.0.0 to 7.0.3, as well as all 6.0.x and 5.5.x versions.
What type of attack does CVE-2010-3718 facilitate?
CVE-2010-3718 facilitates local website applications to conduct directory traversal attacks.
Is it safe to use vulnerable versions of Apache Tomcat if patched?
Even if patched, it is advisable to use the latest versions of Apache Tomcat to avoid vulnerabilities like CVE-2010-3718.