Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088.
| Software | From | Fixed in |
|---|---|---|
| apache / tomcat | 7.0.8 | 7.0.8.x |
| apache / tomcat | 7.0.1 | 7.0.1.x |
| apache / tomcat | 7.0.2 | 7.0.2.x |
| apache / tomcat | 7.0.5 | 7.0.5.x |
| apache / tomcat | 7.0.0 | 7.0.0.x |
| apache / tomcat | 7.0.6 | 7.0.6.x |
| apache / tomcat | 7.0.0-beta | 7.0.0-beta.x |
| apache / tomcat | 7.0.7 | 7.0.7.x |
| apache / tomcat | 7.0.10 | 7.0.10.x |
| apache / tomcat | 7.0.9 | 7.0.9.x |
| apache / tomcat | 7.0.4 | 7.0.4.x |
| apache / tomcat | 7.0.3 | 7.0.3.x |