Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2011-2729

native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to an application.

  • Published: Aug 15, 2011
  • Updated: Apr 13, 2023
  • CVE: CVE-2011-2729
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 5
  • AV:N/AC:L/Au:N/C:P/I:N/A:N

CWEs:

Software From Fixed in
apache / tomcat 5.5.32 5.5.32.x
apache / tomcat 5.5.33 5.5.33.x
apache / tomcat 6.0.30 6.0.30.x
apache / tomcat 6.0.31 6.0.31.x
apache / tomcat 6.0.32 6.0.32.x
apache / apache_commons_daemon 1.0.3 1.0.3.x
apache / apache_commons_daemon 1.0.4 1.0.4.x
apache / apache_commons_daemon 1.0.5 1.0.5.x
apache / apache_commons_daemon 1.0.6 1.0.6.x
apache / tomcat 7.0.0 7.0.0.x
apache / tomcat 7.0.0-beta 7.0.0-beta.x
apache / tomcat 7.0.1 7.0.1.x
apache / tomcat 7.0.2 7.0.2.x
apache / tomcat 7.0.3 7.0.3.x
apache / tomcat 7.0.4 7.0.4.x
apache / tomcat 7.0.5 7.0.5.x
apache / tomcat 7.0.6 7.0.6.x
apache / tomcat 7.0.7 7.0.7.x
apache / tomcat 7.0.8 7.0.8.x
apache / tomcat 7.0.9 7.0.9.x
apache / tomcat 7.0.10 7.0.10.x
apache / tomcat 7.0.11 7.0.11.x
apache / tomcat 7.0.12 7.0.12.x
apache / tomcat 7.0.13 7.0.13.x
apache / tomcat 7.0.14 7.0.14.x
apache / tomcat 7.0.16 7.0.16.x
apache / tomcat 7.0.17 7.0.17.x
apache / tomcat 7.0.19 7.0.19.x