Apache Tomcat '@ServletSecurity' Annotations Security Bypass Vulnerability
BID:46685
Info
Apache Tomcat '@ServletSecurity' Annotations Security Bypass Vulnerability
| Bugtraq ID: | 46685 |
| Class: | Design Error |
| CVE: |
CVE-2011-1088 CVE-2011-1419 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 02 2011 12:00AM |
| Updated: | Jun 25 2012 12:30PM |
| Credit: | Michael McCutcheon |
| Vulnerable: |
Gentoo Linux Apache Software Foundation Tomcat 7.0.8 Apache Software Foundation Tomcat 7.0.6 Apache Software Foundation Tomcat 7.0.4 Apache Software Foundation Tomcat 7.0.3 Apache Software Foundation Tomcat 7.0.2 Apache Software Foundation Tomcat 7.0.1 Apache Software Foundation Tomcat 7.0.1 Apache Software Foundation Tomcat 7.0 Apache Software Foundation Tomcat 7.0.5 Apache Software Foundation Tomcat 7.0.10 Apache Software Foundation Tomcat 7.0 |
| Not Vulnerable: |
Apache Software Foundation Tomcat 7.0.11 |
Discussion
Apache Tomcat '@ServletSecurity' Annotations Security Bypass Vulnerability
Apache Tomcat is prone to a security-bypass vulnerability.
Successful exploits will allow attackers to bypass certain authentication and obtain sensitive information.
Versions prior to Apache Tomcat 7.0.11 are vulnerable.
Apache Tomcat is prone to a security-bypass vulnerability.
Successful exploits will allow attackers to bypass certain authentication and obtain sensitive information.
Versions prior to Apache Tomcat 7.0.11 are vulnerable.
Exploit / POC
Apache Tomcat '@ServletSecurity' Annotations Security Bypass Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apache Tomcat '@ServletSecurity' Annotations Security Bypass Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Apache Tomcat '@ServletSecurity' Annotations Security Bypass Vulnerability
References:
References:
- [SECURITY] Tomcat 7 ignores @ServletSecurity annotations (Apache Tomcat security team)
- Apache Tomcat Homepage (Apache)
- Fixed in Apache Tomcat 7.0.11 (released 11 Mar 2011) (Apache Software Foundation)