Lucene search

K
osvGoogleOSV:GHSA-VCH7-92VF-JM44
HistoryMay 17, 2022 - 2:00 a.m.

Apache Tomcat does not follow ServletSecurity annotations

2022-05-1702:00:34
Google
osv.dev
6

6.6 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

57.2%

Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088.

6.6 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

57.2%