CVE-2011-1183

Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1088 and CVE-2011-1419.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:tomcat:7.0.11:*:*:*:*:*:*:*

History

21 Nov 2024, 01:25

Type Values Removed Values Added
References () http://seclists.org/fulldisclosure/2011/Apr/96 - () http://seclists.org/fulldisclosure/2011/Apr/96 -
References () http://securityreason.com/securityalert/8187 - () http://securityreason.com/securityalert/8187 -
References () http://svn.apache.org/viewvc?view=revision&revision=1087643 - Patch () http://svn.apache.org/viewvc?view=revision&revision=1087643 - Patch
References () http://tomcat.apache.org/security-7.html - () http://tomcat.apache.org/security-7.html -
References () http://www.securityfocus.com/archive/1/517362/100/0/threaded - () http://www.securityfocus.com/archive/1/517362/100/0/threaded -
References () http://www.securityfocus.com/bid/47196 - () http://www.securityfocus.com/bid/47196 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/66675 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/66675 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12701 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12701 -

07 Nov 2023, 02:06

Type Values Removed Values Added
Summary Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1088 and CVE-2011-1419. Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1088 and CVE-2011-1419.

Information

Published : 2011-04-08 15:17

Updated : 2024-11-21 01:25


NVD link : CVE-2011-1183

Mitre link : CVE-2011-1183

CVE.ORG link : CVE-2011-1183


JSON object : View

Products Affected

apache

  • tomcat