First published: Fri Nov 11 2011(Updated: )
org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local users to gain privileges by using an untrusted web application to access the Manager application's functionality.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tomcat | =7.0.0 | |
Tomcat | =7.0.0-beta | |
Tomcat | =7.0.1 | |
Tomcat | =7.0.2 | |
Tomcat | =7.0.3 | |
Tomcat | =7.0.4 | |
Tomcat | =7.0.5 | |
Tomcat | =7.0.6 | |
Tomcat | =7.0.7 | |
Tomcat | =7.0.8 | |
Tomcat | =7.0.9 | |
Tomcat | =7.0.10 | |
Tomcat | =7.0.11 | |
Tomcat | =7.0.12 | |
Tomcat | =7.0.13 | |
Tomcat | =7.0.14 | |
Tomcat | =7.0.15 | |
Tomcat | =7.0.16 | |
Tomcat | =7.0.17 | |
Tomcat | =7.0.18 | |
Tomcat | =7.0.19 | |
Tomcat | =7.0.20 | |
Tomcat | =7.0.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-3376 is rated as a medium severity vulnerability.
To fix CVE-2011-3376, upgrade Apache Tomcat to version 7.0.22 or later.
CVE-2011-3376 affects Apache Tomcat versions from 7.0.0 to 7.0.21.
CVE-2011-3376 is a privilege escalation vulnerability in the Manager application of Apache Tomcat.
Yes, local users can exploit CVE-2011-3376 to gain unauthorized access to the Manager application's capabilities.