Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Tomcat | — | Upgrade Apache Tomcat to the latest available versionUpgrade Apache Tomcat to 6.0.30Upgrade Apache Tomcat to 7.0.4Upgrade Apache Tomcat to 5.5.30 | May 17, 2012 | Feb 10, 2011 |
| Apple Osx Apache | — | Upgrade macOS to the latest versionApply OS X security update 2011-006 | Aug 28, 2015 | Feb 10, 2011 |
| Apple Osx Tomcat | — | Apply OS X security update 2011-006 | Dec 16, 2011 | Feb 10, 2011 |
| Centos_linux | — | Upgrade tomcat5-server-libUpgrade tomcat5Upgrade tomcat5-admin-webappsUpgrade tomcat5-jasper-javadocUpgrade tomcat5-jasperUpgrade tomcat5-webappsUpgrade tomcat5-jsp-2.0-apiUpgrade tomcat5-servlet-2.4-api-javadocUpgrade tomcat5-common-libUpgrade tomcat5-jsp-2.0-api-javadocUpgrade tomcat5-servlet-2.4-api | Dec 1, 2016 | Feb 10, 2011 |
| Gentoo Linux | — | Upgrade www-servers/tomcat. | Oct 30, 2017 | Feb 10, 2011 |
| Hpux | — | Update hpuxwsAPCH32.PHP to the latest versionUpdate hpuxwsAPACHE.AUTH_LDAP2 to the latest versionUpdate hpuxwsAPACHE.APACHE to the latest versionUpdate hpuxwsAPCH32.AUTH_LDAP2 to the latest versionUpdate hpuxwsAPCH32.MOD_JK to the latest versionUpdate hpuxwsAPACHE.PHP to the latest versionUpdate hpuxwsAPACHE.MOD_PERL to the latest versionUpdate hpuxwsAPACHE.MOD_JK to the latest versionUpdate hpuxws22TOMCAT.TOMCAT to the latest versionUpdate hpuxwsAPCH32.AUTH_LDAP to the latest versionUpdate hpuxwsAPACHE.APACHE2 to the latest versionUpdate hpuxwsAPACHE.MOD_PERL2 to the latest versionUpdate hpuxwsAPACHE.PHP2 to the latest versionUpdate hpuxwsAPACHE.AUTH_LDAP to the latest versionUpdate hpuxwsAPCH32.WEBPROXY to the latest versionUpdate hpuxwsAPACHE.MOD_JK2 to the latest versionUpdate hpuxwsAPCH32.MOD_JK2 to the latest versionUpdate hpuxwsAPCH32.APACHE to the latest versionUpdate hpuxwsAPCH32.MOD_PERL to the latest versionUpdate hpuxwsAPCH32.MOD_PERL2 to the latest versionUpdate hpuxwsAPCH32.PHP2 to the latest versionUpdate hpuxwsAPACHE.WEBPROXY to the latest versionUpdate hpuxwsAPCH32.APACHE2 to the latest version | Aug 11, 2017 | Feb 10, 2011 |
| Oracle_linux | — | Upgrade tomcat5-jasper-javadocUpgrade tomcat5-admin-webappsUpgrade tomcat5-server-libUpgrade tomcat6-docs-webappUpgrade tomcat6-admin-webappsUpgrade tomcat6-libUpgrade tomcat6-webappsUpgrade tomcat6-jsp-2.1-apiUpgrade tomcat5-jsp-2.0-api-javadocUpgrade tomcat5-servlet-2.4-api-javadocUpgrade tomcat5-common-libUpgrade tomcat5Upgrade tomcat5-servlet-2.4-apiUpgrade tomcat6-el-2.1-apiUpgrade tomcat5-jasperUpgrade tomcat6-servlet-2.5-apiUpgrade tomcat6-javadocUpgrade tomcat6Upgrade tomcat5-webappsUpgrade tomcat5-jsp-2.0-api | Oct 16, 2024 | Feb 10, 2011 |
| Suse | — | Upgrade tomcat6-jsp-2_1-apiUpgrade tomcat6-javadocUpgrade tomcat6Upgrade tomcat6-servlet-2_5-apiUpgrade tomcat6-libUpgrade tomcat6-webappsUpgrade tomcat6-admin-webappsUpgrade tomcat6-docs-webapp | Feb 17, 2015 | Jul 17, 2014 |
| Ubuntu | — | Upgrade tomcat6-adminUpgrade libtomcat6-java | Nov 8, 2024 | Feb 10, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub