CVE-2011-2481

Apache Tomcat 7.0.x before 7.0.17 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application. NOTE: this vulnerability exists because of a CVE-2009-0783 regression.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:tomcat:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:7.0.0:beta:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:7.0.3:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:7.0.4:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:7.0.5:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:7.0.6:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:7.0.7:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:7.0.8:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:7.0.9:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:7.0.10:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:7.0.11:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:7.0.12:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:7.0.13:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:7.0.14:*:*:*:*:*:*:*

History

21 Nov 2024, 01:28

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=139344343412337&w=2 - () http://marc.info/?l=bugtraq&m=139344343412337&w=2 -
References () http://secunia.com/advisories/57126 - () http://secunia.com/advisories/57126 -
References () http://securitytracker.com/id?1025924 - () http://securitytracker.com/id?1025924 -
References () http://svn.apache.org/viewvc?view=revision&revision=1137753 - Patch () http://svn.apache.org/viewvc?view=revision&revision=1137753 - Patch
References () http://svn.apache.org/viewvc?view=revision&revision=1138788 - Patch () http://svn.apache.org/viewvc?view=revision&revision=1138788 - Patch
References () http://tomcat.apache.org/security-7.html - Patch, Vendor Advisory () http://tomcat.apache.org/security-7.html - Patch, Vendor Advisory
References () http://www.securityfocus.com/bid/49147 - () http://www.securityfocus.com/bid/49147 -
References () https://issues.apache.org/bugzilla/show_bug.cgi?id=51395 - Exploit () https://issues.apache.org/bugzilla/show_bug.cgi?id=51395 - Exploit

07 Nov 2023, 02:07

Type Values Removed Values Added
Summary Apache Tomcat 7.0.x before 7.0.17 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application. NOTE: this vulnerability exists because of a CVE-2009-0783 regression. Apache Tomcat 7.0.x before 7.0.17 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application. NOTE: this vulnerability exists because of a CVE-2009-0783 regression.

Information

Published : 2011-08-15 21:55

Updated : 2024-11-21 01:28


NVD link : CVE-2011-2481

Mitre link : CVE-2011-2481

CVE.ORG link : CVE-2011-2481


JSON object : View

Products Affected

apache

  • tomcat