CVE-2011-1582
published 2011-05-20CVE-2011-1582: Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security constraints that have been configured through annotations…
PriorityP428medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
6.02%
92.6th percentile
Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security constraints that have been configured through annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088, CVE-2011-1183, and CVE-2011-1419.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
ghsa5.8MEDIUM
osv5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Access restriction bypass in Apache Tomcat
ghsa·2022-05-14·CVSS 5.8
CVE-2011-1582 [MEDIUM] Access restriction bypass in Apache Tomcat
Access restriction bypass in Apache Tomcat
Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security constraints that have been configured through annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088, CVE-2011-1183, and CVE-2011-1419.
OSV
Access restriction bypass in Apache Tomcat
osv·2022-05-14·CVSS 5.8
CVE-2011-1582 [MEDIUM] Access restriction bypass in Apache Tomcat
Access restriction bypass in Apache Tomcat
Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security constraints that have been configured through annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088, CVE-2011-1183, and CVE-2011-1419.
Red Hat
tomcat: various flaws due not following ServletSecurity annotations
vendor_redhat·2011-03-02·CVSS 5.8
CVE-2011-1582 [MEDIUM] tomcat: various flaws due not following ServletSecurity annotations
tomcat: various flaws due not following ServletSecurity annotations
Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security constraints that have been configured through annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088, CVE-2011-1183, and CVE-2011-1419.
Statement: Not vulnerable. This issue did not affect the versions of Apache Tomcat 5 as shipped with Red Hat Enterprise Linux 5, Red Hat Developer Suite 3, Red Hat Certificate System 7.3, Red Hat Network Satellite 5.3.0 and earlier versions and JBoss Enterprise Web Server 1.0. It did not affect the versions of Apache Tomcat 6 as shipped with Red Hat Enterprise Linux
No detection rules found.
No public exploits indexed.
http://mail-archives.apache.org/mod_mbox/www-announce/201105.mbox/%3C4DD26E30.2060103%40apache.org%3Ehttp://securityreason.com/securityalert/8256http://svn.apache.org/viewvc?view=revision&revision=1100832http://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.14_%28released_12_May_2011%29http://www.securityfocus.com/archive/1/518032/100/0/threadedhttp://www.securityfocus.com/bid/47886http://www.vupen.com/english/advisories/2011/1255https://exchange.xforce.ibmcloud.com/vulnerabilities/67515http://mail-archives.apache.org/mod_mbox/www-announce/201105.mbox/%3C4DD26E30.2060103%40apache.org%3Ehttp://securityreason.com/securityalert/8256http://svn.apache.org/viewvc?view=revision&revision=1100832http://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.14_%28released_12_May_2011%29http://www.securityfocus.com/archive/1/518032/100/0/threadedhttp://www.securityfocus.com/bid/47886http://www.vupen.com/english/advisories/2011/1255https://exchange.xforce.ibmcloud.com/vulnerabilities/67515
2011-05-20
Published