4.4 Medium
CVSS2
Attack Vector
LOCAL
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:L/AC:M/Au:N/C:P/I:P/A:P
0.0005 Low
EPSS
Percentile
17.2%
Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before
7.0.19, when sendfile is enabled for the HTTP APR or HTTP NIO connector,
does not validate certain request attributes, which allows local users to
bypass intended file access restrictions or cause a denial of service
(infinite loop or JVM crash) by leveraging an untrusted web application.