First published: Fri Nov 11 2011(Updated: )
org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local users to gain privileges by using an untrusted web application to access the Manager application's functionality.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Tomcat | =7.0.12 | |
Apache Tomcat | =7.0.20 | |
Apache Tomcat | =7.0.8 | |
Apache Tomcat | =7.0.1 | |
Apache Tomcat | =7.0.2 | |
Apache Tomcat | =7.0.5 | |
Apache Tomcat | =7.0.0 | |
Apache Tomcat | =7.0.6 | |
Apache Tomcat | =7.0.18 | |
Apache Tomcat | =7.0.14 | |
Apache Tomcat | =7.0.11 | |
Apache Tomcat | =7.0.0-beta | |
Apache Tomcat | =7.0.7 | |
Apache Tomcat | =7.0.13 | |
Apache Tomcat | =7.0.15 | |
Apache Tomcat | =7.0.19 | |
Apache Tomcat | =7.0.16 | |
Apache Tomcat | =7.0.10 | |
Apache Tomcat | =7.0.21 | |
Apache Tomcat | =7.0.17 | |
Apache Tomcat | =7.0.9 | |
Apache Tomcat | =7.0.4 | |
Apache Tomcat | =7.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.