Lucene search

K
cvelistRedhatCVELIST:CVE-2011-2729
HistoryAug 15, 2011 - 9:00 p.m.

CVE-2011-2729

2011-08-1521:00:00
redhat
www.cve.org

4.1 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

57.9%

native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to an application.

References

4.1 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

57.9%