← Back

CVE-2011-3376

nvd nist
Published: Nov 11, 2011Modified: Apr 29, 2026

JSON object

Loading...
4.4
Vector
AV:L/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 3.4 / Impact: 6.4
Source: NVD

Description

org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local users to gain privileges by using an untrusted web application to access the Manager application's functionality.

Affected (23)

Products: Apache: Tomcat
1 product
Tomcat
Configuration A
23 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Version 7.0.0
Version 7.0.0 beta
Version 7.0.10
Version 7.0.11
Version 7.0.12
Version 7.0.13
Version 7.0.14
Version 7.0.15
Version 7.0.16
Version 7.0.17
Version 7.0.18
Version 7.0.19
Version 7.0.1
Version 7.0.20
Version 7.0.21
Version 7.0.2
Version 7.0.3
Version 7.0.4
Version 7.0.5
Version 7.0.6
Version 7.0.7
Version 7.0.8
Version 7.0.9

Related CWEs

Timeline

No history available yet.