Apache Tomcat 7.0.x before 7.0.17 permits web applications to replace...
Vulnerability Description
Apache Tomcat 7.0.x before 7.0.17 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application. NOTE: this vulnerability exists because of a CVE-2009-0783 regression.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-2481
Credits & Attribution
No credits recorded in the NVD database.
References
- http://tomcat.apache.org/security-7.html
- http://svn.apache.org/viewvc?view=revision&revision=1138788
- http://securitytracker.com/id?1025924
- https://issues.apache.org/bugzilla/show_bug.cgi?id=51395
- http://secunia.com/advisories/57126
- http://svn.apache.org/viewvc?view=revision&revision=1137753
- http://www.securityfocus.com/bid/49147
- http://marc.info/?l=bugtraq&m=139344343412337&w=2
More from apache
View All →Affected Vendor
apache
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.