CVE-2011-1088
published 2011-03-14CVE-2011-1088: Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP…
PriorityP336medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
6.45%
93.0th percentile
Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| djangoproject | django | >= 0 < 1.2.7 | 1.2.7 |
| djangoproject | django | >= 1.3 < 1.3.1 | 1.3.1 |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
ghsa6.4MEDIUM
osv5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
tomcat: various flaws due not following ServletSecurity annotations
vendor_redhat·2011-03-02·CVSS 5.8
CVE-2011-1419 [MEDIUM] tomcat: various flaws due not following ServletSecurity annotations
tomcat: various flaws due not following ServletSecurity annotations
Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088.
Package: tomcat5 (Red Hat Enterprise Linux 5) - Not affected
Package: tomcat6 (Red Hat Enterprise Linux 6) - Not affected
Red Hat
tomcat: various flaws due not following ServletSecurity annotations
vendor_redhat·2011-03-02·CVSS 5.8
CVE-2011-1088 [MEDIUM] tomcat: various flaws due not following ServletSecurity annotations
tomcat: various flaws due not following ServletSecurity annotations
Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application.
Statement: Not vulnerable. This issue did not affect the versions of Apache Tomcat 5 as shipped with Red Hat Enterprise Linux 5, Red Hat Developer Suite 3,
Red Hat Certificate System 7.3, Red Hat Network Satellite 5.3.0 and earlier versions and JBoss Enterprise Web Server 1.0. It did not affect the versions of Apache Tomcat 6 as shipped with Red Hat Enterprise Linux 6 and JBoss Enterprise Web Server 1.0. It also did not affect the versions of jbossweb as shipped with JBoss Enterprise Application Platform 4.3.0 and earlier versions, as thi
Red Hat
tomcat: various flaws due not following ServletSecurity annotations
vendor_redhat·2011-03-02·CVSS 5.8
CVE-2011-1582 [MEDIUM] tomcat: various flaws due not following ServletSecurity annotations
tomcat: various flaws due not following ServletSecurity annotations
Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security constraints that have been configured through annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088, CVE-2011-1183, and CVE-2011-1419.
Statement: Not vulnerable. This issue did not affect the versions of Apache Tomcat 5 as shipped with Red Hat Enterprise Linux 5, Red Hat Developer Suite 3, Red Hat Certificate System 7.3, Red Hat Network Satellite 5.3.0 and earlier versions and JBoss Enterprise Web Server 1.0. It did not affect the versions of Apache Tomcat 6 as shipped with Red Hat Enterprise Linux
Red Hat
tomcat: various flaws due not following ServletSecurity annotations
vendor_redhat·2011-03-02·CVSS 5.8
CVE-2011-1183 [MEDIUM] tomcat: various flaws due not following ServletSecurity annotations
tomcat: various flaws due not following ServletSecurity annotations
Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1088 and CVE-2011-1419.
Statement: Not vulnerable. This issue did not affect the versions of Apache Tomcat 5 as shipped with Red Hat Enterprise Linux 5, Red Hat Developer Suite 3, Red Hat Certificate System 7.3, Red Hat Network Satellite 5.3.0 and earlier versions and JBoss Enterprise Web Server 1.0. It did not affect the versions of Apache Tomcat 6 as shipped with Red Hat Enterprise Linux 6 and JBoss Enterprise Web Server 1
OSV
Apache Tomcat does not follow ServletSecurity annotations
osv·2022-05-17·CVSS 5.8
CVE-2011-1419 [MEDIUM] Apache Tomcat does not follow ServletSecurity annotations
Apache Tomcat does not follow ServletSecurity annotations
Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088.
GHSA
Apache Tomcat does not follow ServletSecurity annotations
ghsa·2022-05-17·CVSS 5.8
CVE-2011-1419 [MEDIUM] CWE-284 Apache Tomcat does not follow ServletSecurity annotations
Apache Tomcat does not follow ServletSecurity annotations
Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088.
GHSA
Access restriction bypass in Apache Tomcat
ghsa·2022-05-14·CVSS 5.8
CVE-2011-1582 [MEDIUM] Access restriction bypass in Apache Tomcat
Access restriction bypass in Apache Tomcat
Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security constraints that have been configured through annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088, CVE-2011-1183, and CVE-2011-1419.
OSV
Apache Tomcat allows remote attackers to bypass intended access restrictions
osv·2022-05-14
CVE-2011-1088 [MEDIUM] Apache Tomcat allows remote attackers to bypass intended access restrictions
Apache Tomcat allows remote attackers to bypass intended access restrictions
Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application.
OSV
Access restriction bypass in Apache Tomcat
osv·2022-05-14·CVSS 5.8
CVE-2011-1582 [MEDIUM] Access restriction bypass in Apache Tomcat
Access restriction bypass in Apache Tomcat
Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security constraints that have been configured through annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088, CVE-2011-1183, and CVE-2011-1419.
OSV
Access controll bypass in Apache Tomcat
osv·2022-05-14·CVSS 5.8
CVE-2011-1183 [MEDIUM] Access controll bypass in Apache Tomcat
Access controll bypass in Apache Tomcat
Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1088 and CVE-2011-1419.
GHSA
Apache Tomcat allows remote attackers to bypass intended access restrictions
ghsa·2022-05-14
CVE-2011-1088 [MEDIUM] Apache Tomcat allows remote attackers to bypass intended access restrictions
Apache Tomcat allows remote attackers to bypass intended access restrictions
Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application.
GHSA
Access controll bypass in Apache Tomcat
ghsa·2022-05-14·CVSS 5.8
CVE-2011-1183 [MEDIUM] Access controll bypass in Apache Tomcat
Access controll bypass in Apache Tomcat
Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1088 and CVE-2011-1419.
GHSA
Denial of service in django
ghsa·2018-07-23·CVSS 6.4
CVE-2011-4137 [MEDIUM] CWE-1088 Denial of service in django
Denial of service in django
The verify_exists functionality in the URLField implementation in Django before 1.2.7 and 1.3.x before 1.3.1 relies on Python libraries that attempt access to an arbitrary URL with no timeout, which allows remote attackers to cause a denial of service (resource consumption) via a URL associated with (1) a slow response, (2) a completed TCP connection with no application data sent, or (3) a large amount of application data, a related issue to CVE-2011-1521.
No detection rules found.
No public exploits indexed.
http://mail-archives.apache.org/mod_mbox/www-announce/201103.mbox/%3C4D6E74FF.7050106%40apache.org%3Ehttp://markmail.org/message/lzx5273wsgl5pob6http://markmail.org/message/yzmyn44f5aetmm2rhttp://secunia.com/advisories/43684http://svn.apache.org/viewvc?view=revision&revision=1076586http://svn.apache.org/viewvc?view=revision&revision=1076587http://svn.apache.org/viewvc?view=revision&revision=1077995http://tomcat.apache.org/security-7.htmlhttp://www.osvdb.org/71027http://www.securityfocus.com/archive/1/517013/100/0/threadedhttp://www.securityfocus.com/bid/46685http://www.securitytracker.com/id?1025215http://www.vupen.com/english/advisories/2011/0563https://exchange.xforce.ibmcloud.com/vulnerabilities/65971http://mail-archives.apache.org/mod_mbox/www-announce/201103.mbox/%3C4D6E74FF.7050106%40apache.org%3Ehttp://markmail.org/message/lzx5273wsgl5pob6http://markmail.org/message/yzmyn44f5aetmm2rhttp://secunia.com/advisories/43684http://svn.apache.org/viewvc?view=revision&revision=1076586http://svn.apache.org/viewvc?view=revision&revision=1076587http://svn.apache.org/viewvc?view=revision&revision=1077995http://tomcat.apache.org/security-7.htmlhttp://www.osvdb.org/71027http://www.securityfocus.com/archive/1/517013/100/0/threadedhttp://www.securityfocus.com/bid/46685http://www.securitytracker.com/id?1025215http://www.vupen.com/english/advisories/2011/0563https://exchange.xforce.ibmcloud.com/vulnerabilities/65971
2011-03-14
Published