Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.812257
Kategorie:Web Servers
Titel:Apache Tomcat 'ServletSecurity' Annotations Security Bypass Vulnerability - Linux
Zusammenfassung:Apache Tomcat is prone to a security bypass vulnerability.
Beschreibung:Summary:
Apache Tomcat is prone to a security bypass vulnerability.

Vulnerability Insight:
The flaw is due to when a web application
was started, ServletSecurity annotations were ignored. This meant that some
areas of the application may not have been protected as expected.

Vulnerability Impact:
Successful exploitation will allow remote
attackers to bypass certain authentication and obtain sensitive information.

Affected Software/OS:
Apache Tomcat versions 7.0.0 to 7.0.10
on Linux

Solution:
Upgrade to Tomcat version 7.0.11 or later.

CVSS Score:
5.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2011-1088
1025215
http://www.securitytracker.com/id?1025215
20110315 [SECURITY] CVE-2011-1088 Apache Tomcat security constraint bypass
http://www.securityfocus.com/archive/1/517013/100/0/threaded
43684
http://secunia.com/advisories/43684
46685
http://www.securityfocus.com/bid/46685
71027
http://www.osvdb.org/71027
ADV-2011-0563
http://www.vupen.com/english/advisories/2011/0563
[announce] 20110302 [SECURITY] Tomcat 7 ignores @ServletSecurity annotations
http://mail-archives.apache.org/mod_mbox/www-announce/201103.mbox/%3C4D6E74FF.7050106%40apache.org%3E
[users] 20110302 Re: @DenyAll does nothing
http://markmail.org/message/lzx5273wsgl5pob6
http://markmail.org/message/yzmyn44f5aetmm2r
http://svn.apache.org/viewvc?view=revision&revision=1076586
http://svn.apache.org/viewvc?view=revision&revision=1076587
http://svn.apache.org/viewvc?view=revision&revision=1077995
http://tomcat.apache.org/security-7.html
tomcat-servletsecurity-sec-bypass(65971)
https://exchange.xforce.ibmcloud.com/vulnerabilities/65971
Common Vulnerability Exposure (CVE) ID: CVE-2011-1419
BugTraq ID: 46685
http://mail-archives.apache.org/mod_mbox/www-announce/201103.mbox/%3C4D6E74FF.7050106@apache.org%3E
http://marc.info/?l=tomcat-user&m=129966773405409&w=2
http://securityreason.com/securityalert/8131
XForce ISS Database: apache-servletsecurity-sec-bypass(66154)
https://exchange.xforce.ibmcloud.com/vulnerabilities/66154
XForce ISS Database: tomcat-servletsecurity-sec-bypass(65971)
CopyrightCopyright (C) 2017 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.