CVE-2011-1183
published 2011-04-08CVE-2011-1183: Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access…
PriorityP434medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
6.16%
92.7th percentile
Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1088 and CVE-2011-1419.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
ghsa5.8MEDIUM
osv5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Access restriction bypass in Apache Tomcat
ghsa·2022-05-14·CVSS 5.8
CVE-2011-1582 [MEDIUM] Access restriction bypass in Apache Tomcat
Access restriction bypass in Apache Tomcat
Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security constraints that have been configured through annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088, CVE-2011-1183, and CVE-2011-1419.
OSV
Access restriction bypass in Apache Tomcat
osv·2022-05-14·CVSS 5.8
CVE-2011-1582 [MEDIUM] Access restriction bypass in Apache Tomcat
Access restriction bypass in Apache Tomcat
Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security constraints that have been configured through annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088, CVE-2011-1183, and CVE-2011-1419.
OSV
Access controll bypass in Apache Tomcat
osv·2022-05-14·CVSS 5.8
CVE-2011-1183 [MEDIUM] Access controll bypass in Apache Tomcat
Access controll bypass in Apache Tomcat
Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1088 and CVE-2011-1419.
GHSA
Access controll bypass in Apache Tomcat
ghsa·2022-05-14·CVSS 5.8
CVE-2011-1183 [MEDIUM] Access controll bypass in Apache Tomcat
Access controll bypass in Apache Tomcat
Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1088 and CVE-2011-1419.
Red Hat
tomcat: various flaws due not following ServletSecurity annotations
vendor_redhat·2011-03-02·CVSS 5.8
CVE-2011-1582 [MEDIUM] tomcat: various flaws due not following ServletSecurity annotations
tomcat: various flaws due not following ServletSecurity annotations
Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security constraints that have been configured through annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088, CVE-2011-1183, and CVE-2011-1419.
Statement: Not vulnerable. This issue did not affect the versions of Apache Tomcat 5 as shipped with Red Hat Enterprise Linux 5, Red Hat Developer Suite 3, Red Hat Certificate System 7.3, Red Hat Network Satellite 5.3.0 and earlier versions and JBoss Enterprise Web Server 1.0. It did not affect the versions of Apache Tomcat 6 as shipped with Red Hat Enterprise Linux
Red Hat
tomcat: various flaws due not following ServletSecurity annotations
vendor_redhat·2011-03-02·CVSS 5.8
CVE-2011-1183 [MEDIUM] tomcat: various flaws due not following ServletSecurity annotations
tomcat: various flaws due not following ServletSecurity annotations
Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1088 and CVE-2011-1419.
Statement: Not vulnerable. This issue did not affect the versions of Apache Tomcat 5 as shipped with Red Hat Enterprise Linux 5, Red Hat Developer Suite 3, Red Hat Certificate System 7.3, Red Hat Network Satellite 5.3.0 and earlier versions and JBoss Enterprise Web Server 1.0. It did not affect the versions of Apache Tomcat 6 as shipped with Red Hat Enterprise Linux 6 and JBoss Enterprise Web Server 1
No detection rules found.
No public exploits indexed.
http://seclists.org/fulldisclosure/2011/Apr/96http://securityreason.com/securityalert/8187http://svn.apache.org/viewvc?view=revision&revision=1087643http://tomcat.apache.org/security-7.htmlhttp://www.securityfocus.com/archive/1/517362/100/0/threadedhttp://www.securityfocus.com/bid/47196https://exchange.xforce.ibmcloud.com/vulnerabilities/66675https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12701http://seclists.org/fulldisclosure/2011/Apr/96http://securityreason.com/securityalert/8187http://svn.apache.org/viewvc?view=revision&revision=1087643http://tomcat.apache.org/security-7.htmlhttp://www.securityfocus.com/archive/1/517362/100/0/threadedhttp://www.securityfocus.com/bid/47196https://exchange.xforce.ibmcloud.com/vulnerabilities/66675https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12701
2011-04-08
Published