CVE-2011-2481
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/08/2011
Last modified:
11/04/2025
Description
Apache Tomcat 7.0.x before 7.0.17 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application. NOTE: this vulnerability exists because of a CVE-2009-0783 regression.
Impact
Base Score 2.0
4.60
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:apache:tomcat:7.0.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:apache:tomcat:7.0.0:beta:*:*:*:*:*:* | ||
cpe:2.3:a:apache:tomcat:7.0.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:apache:tomcat:7.0.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:apache:tomcat:7.0.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:apache:tomcat:7.0.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:apache:tomcat:7.0.5:*:*:*:*:*:*:* | ||
cpe:2.3:a:apache:tomcat:7.0.6:*:*:*:*:*:*:* | ||
cpe:2.3:a:apache:tomcat:7.0.7:*:*:*:*:*:*:* | ||
cpe:2.3:a:apache:tomcat:7.0.8:*:*:*:*:*:*:* | ||
cpe:2.3:a:apache:tomcat:7.0.9:*:*:*:*:*:*:* | ||
cpe:2.3:a:apache:tomcat:7.0.10:*:*:*:*:*:*:* | ||
cpe:2.3:a:apache:tomcat:7.0.11:*:*:*:*:*:*:* | ||
cpe:2.3:a:apache:tomcat:7.0.12:*:*:*:*:*:*:* | ||
cpe:2.3:a:apache:tomcat:7.0.13:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://marc.info/?l=bugtraq&m=139344343412337&w=2
- http://secunia.com/advisories/57126
- http://securitytracker.com/id?1025924=
- http://svn.apache.org/viewvc?view=revision&revision=1137753
- http://svn.apache.org/viewvc?view=revision&revision=1138788
- http://tomcat.apache.org/security-7.html
- http://www.securityfocus.com/bid/49147
- https://issues.apache.org/bugzilla/show_bug.cgi?id=51395
- http://marc.info/?l=bugtraq&m=139344343412337&w=2
- http://secunia.com/advisories/57126
- http://securitytracker.com/id?1025924=
- http://svn.apache.org/viewvc?view=revision&revision=1137753
- http://svn.apache.org/viewvc?view=revision&revision=1138788
- http://tomcat.apache.org/security-7.html
- http://www.securityfocus.com/bid/49147
- https://issues.apache.org/bugzilla/show_bug.cgi?id=51395