Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-3718

Опубликовано: 05 фев. 2011
Источник: redhat
CVSS2: 4
EPSS Низкий

Описание

Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=675792tomcat: file permission bypass flaw

EPSS

Процентиль: 54%
0.00304
Низкий

4 Medium

CVSS2

Связанные уязвимости

ubuntu
около 15 лет назад

Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.

nvd
около 15 лет назад

Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.

debian
около 15 лет назад

Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running with ...

github
почти 4 года назад

Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat

oracle-oval
почти 15 лет назад

ELSA-2011-0791: tomcat6 security and bug fix update (MODERATE)

EPSS

Процентиль: 54%
0.00304
Низкий

4 Medium

CVSS2

Уязвимость CVE-2010-3718