VDB
CVE-2011-1419
CVE-2011-1419
PUBLISHED
CVSS 5.800000190734863 MEDIUM
Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088.
EPSS 16.10% · 94.9th percentile
Risk Scores
CVSS 2.0
5.800000190734863
EPSS Score
16.10%
94.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | * |
| Maven | org.apache.tomcat:tomcat | 7.0 |
| apache | tomcat | 7.0.0, 7.0.1, 7.0.2 |
Timeline
- Mar 14, 2011 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 7, 2023 EPSS Score
References
- 46685 vdb
- 8131 third-party-advisory
- http://svn.apache.org/viewvc?view=revision&revision=1079752 url
- [users] 20110302 Re: @DenyAll does nothing mailing-list
- ADV-2011-0563 vdb
- 71027 vdb
- [users] 20110302 Re: @DenyAll does nothing mailing-list
- [users] 20110309 [SECURITY] Tomcat 7 ignores @ServletSecurity annotations mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2011-1419 advisory
- https://github.com/apache/tomcat/commit/0ff4905158b77787a7f3aca55c9dec93456665dc url
- https://github.com/apache/tomcat/commit/3e5b0455483eed55752047073e92403bfca8d3ec url
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65971 url
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66154 url
- https://github.com/apache/tomcat package
- https://web.archive.org/web/20110307182442/http://markmail.org/message/yzmyn44f5aetmm2r url
- https://web.archive.org/web/20110323002552/http://markmail.org/message/lzx5273wsgl5pob6 url
- https://web.archive.org/web/20170202135440/http://www.securityfocus.com/bid/46685 url
- http://mail-archives.apache.org/mod_mbox/www-announce/201103.mbox/%3C4D6E74FF.7050106@apache.org%3E url
- http://mail-archives.apache.org/mod_mbox/www-announce/201103.mbox/%3C4D6E74FF.7050106%40apache.org%3E technical
- http://secunia.com/advisories/43684 advisory
…and 1 more