Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-3376

Опубликовано: 11 нояб. 2011
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.4

Описание

org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local users to gain privileges by using an untrusted web application to access the Manager application's functionality.

РелизСтатусПримечание
devel

not-affected

7.0.22-1
hardy

DNE

lucid

DNE

maverick

DNE

natty

DNE

oneiric

released

7.0.21-1ubuntu0.1
precise

not-affected

7.0.22-1
quantal

not-affected

7.0.22-1
upstream

released

7.0.22-1

Показывать по

Ссылки на источники

EPSS

Процентиль: 53%
0.00299
Низкий

4.4 Medium

CVSS2

Связанные уязвимости

redhat
около 14 лет назад

org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local users to gain privileges by using an untrusted web application to access the Manager application's functionality.

nvd
почти 14 лет назад

org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local users to gain privileges by using an untrusted web application to access the Manager application's functionality.

debian
почти 14 лет назад

org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat ...

github
больше 3 лет назад

org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local users to gain privileges by using an untrusted web application to access the Manager application's functionality.

EPSS

Процентиль: 53%
0.00299
Низкий

4.4 Medium

CVSS2

Уязвимость CVE-2011-3376