CVE-2011-1419
published 2011-03-14CVE-2011-1419: Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers to bypass…
PriorityP334medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
6.54%
93.1th percentile
Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
ghsa5.8MEDIUM
osv5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
tomcat: various flaws due not following ServletSecurity annotations
vendor_redhat·2011-03-02·CVSS 5.8
CVE-2011-1419 [MEDIUM] tomcat: various flaws due not following ServletSecurity annotations
tomcat: various flaws due not following ServletSecurity annotations
Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088.
Package: tomcat5 (Red Hat Enterprise Linux 5) - Not affected
Package: tomcat6 (Red Hat Enterprise Linux 6) - Not affected
Red Hat
tomcat: various flaws due not following ServletSecurity annotations
vendor_redhat·2011-03-02·CVSS 5.8
CVE-2011-1582 [MEDIUM] tomcat: various flaws due not following ServletSecurity annotations
tomcat: various flaws due not following ServletSecurity annotations
Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security constraints that have been configured through annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088, CVE-2011-1183, and CVE-2011-1419.
Statement: Not vulnerable. This issue did not affect the versions of Apache Tomcat 5 as shipped with Red Hat Enterprise Linux 5, Red Hat Developer Suite 3, Red Hat Certificate System 7.3, Red Hat Network Satellite 5.3.0 and earlier versions and JBoss Enterprise Web Server 1.0. It did not affect the versions of Apache Tomcat 6 as shipped with Red Hat Enterprise Linux
Red Hat
tomcat: various flaws due not following ServletSecurity annotations
vendor_redhat·2011-03-02·CVSS 5.8
CVE-2011-1183 [MEDIUM] tomcat: various flaws due not following ServletSecurity annotations
tomcat: various flaws due not following ServletSecurity annotations
Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1088 and CVE-2011-1419.
Statement: Not vulnerable. This issue did not affect the versions of Apache Tomcat 5 as shipped with Red Hat Enterprise Linux 5, Red Hat Developer Suite 3, Red Hat Certificate System 7.3, Red Hat Network Satellite 5.3.0 and earlier versions and JBoss Enterprise Web Server 1.0. It did not affect the versions of Apache Tomcat 6 as shipped with Red Hat Enterprise Linux 6 and JBoss Enterprise Web Server 1
OSV
Apache Tomcat does not follow ServletSecurity annotations
osv·2022-05-17·CVSS 5.8
CVE-2011-1419 [MEDIUM] Apache Tomcat does not follow ServletSecurity annotations
Apache Tomcat does not follow ServletSecurity annotations
Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088.
GHSA
Apache Tomcat does not follow ServletSecurity annotations
ghsa·2022-05-17·CVSS 5.8
CVE-2011-1419 [MEDIUM] CWE-284 Apache Tomcat does not follow ServletSecurity annotations
Apache Tomcat does not follow ServletSecurity annotations
Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088.
GHSA
Access restriction bypass in Apache Tomcat
ghsa·2022-05-14·CVSS 5.8
CVE-2011-1582 [MEDIUM] Access restriction bypass in Apache Tomcat
Access restriction bypass in Apache Tomcat
Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security constraints that have been configured through annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088, CVE-2011-1183, and CVE-2011-1419.
OSV
Access restriction bypass in Apache Tomcat
osv·2022-05-14·CVSS 5.8
CVE-2011-1582 [MEDIUM] Access restriction bypass in Apache Tomcat
Access restriction bypass in Apache Tomcat
Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security constraints that have been configured through annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088, CVE-2011-1183, and CVE-2011-1419.
OSV
Access controll bypass in Apache Tomcat
osv·2022-05-14·CVSS 5.8
CVE-2011-1183 [MEDIUM] Access controll bypass in Apache Tomcat
Access controll bypass in Apache Tomcat
Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1088 and CVE-2011-1419.
GHSA
Access controll bypass in Apache Tomcat
ghsa·2022-05-14·CVSS 5.8
CVE-2011-1183 [MEDIUM] Access controll bypass in Apache Tomcat
Access controll bypass in Apache Tomcat
Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1088 and CVE-2011-1419.
No detection rules found.
No public exploits indexed.
http://mail-archives.apache.org/mod_mbox/www-announce/201103.mbox/%3C4D6E74FF.7050106%40apache.org%3Ehttp://marc.info/?l=tomcat-user&m=129966773405409&w=2http://markmail.org/message/lzx5273wsgl5pob6http://markmail.org/message/yzmyn44f5aetmm2rhttp://secunia.com/advisories/43684http://securityreason.com/securityalert/8131http://svn.apache.org/viewvc?view=revision&revision=1079752http://tomcat.apache.org/security-7.htmlhttp://www.osvdb.org/71027http://www.securityfocus.com/bid/46685http://www.vupen.com/english/advisories/2011/0563https://exchange.xforce.ibmcloud.com/vulnerabilities/65971https://exchange.xforce.ibmcloud.com/vulnerabilities/66154http://mail-archives.apache.org/mod_mbox/www-announce/201103.mbox/%3C4D6E74FF.7050106%40apache.org%3Ehttp://marc.info/?l=tomcat-user&m=129966773405409&w=2http://markmail.org/message/lzx5273wsgl5pob6http://markmail.org/message/yzmyn44f5aetmm2rhttp://secunia.com/advisories/43684http://securityreason.com/securityalert/8131http://svn.apache.org/viewvc?view=revision&revision=1079752http://tomcat.apache.org/security-7.htmlhttp://www.osvdb.org/71027http://www.securityfocus.com/bid/46685http://www.vupen.com/english/advisories/2011/0563https://exchange.xforce.ibmcloud.com/vulnerabilities/65971https://exchange.xforce.ibmcloud.com/vulnerabilities/66154
2011-03-14
Published