First published: Mon Aug 15 2011(Updated: )
Apache Tomcat 7.0.x before 7.0.17 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application. NOTE: this vulnerability exists because of a CVE-2009-0783 regression.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.apache.tomcat:tomcat | >=7.0.0<7.0.17 | 7.0.17 |
Apache Tomcat | =7.0.0 | |
Apache Tomcat | =7.0.0-beta | |
Apache Tomcat | =7.0.1 | |
Apache Tomcat | =7.0.2 | |
Apache Tomcat | =7.0.3 | |
Apache Tomcat | =7.0.4 | |
Apache Tomcat | =7.0.5 | |
Apache Tomcat | =7.0.6 | |
Apache Tomcat | =7.0.7 | |
Apache Tomcat | =7.0.8 | |
Apache Tomcat | =7.0.9 | |
Apache Tomcat | =7.0.10 | |
Apache Tomcat | =7.0.11 | |
Apache Tomcat | =7.0.12 | |
Apache Tomcat | =7.0.13 | |
Apache Tomcat | =7.0.14 | |
=7.0.0 | ||
=7.0.0-beta | ||
=7.0.1 | ||
=7.0.2 | ||
=7.0.3 | ||
=7.0.4 | ||
=7.0.5 | ||
=7.0.6 | ||
=7.0.7 | ||
=7.0.8 | ||
=7.0.9 | ||
=7.0.10 | ||
=7.0.11 | ||
=7.0.12 | ||
=7.0.13 | ||
=7.0.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2481 is classified as a medium-severity vulnerability.
To fix CVE-2011-2481, upgrade Apache Tomcat to version 7.0.17 or later.
CVE-2011-2481 is an XML parser vulnerability that can allow local users to access or modify web application files.
CVE-2011-2481 affects all Apache Tomcat versions prior to 7.0.17.
CVE-2011-2481 allows unauthorized access to important configuration files such as web.xml, context.xml, and tld files.