Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:4385
HistoryJun 07, 2017 - 2:00 a.m.

Security Constraint Bypass

2017-06-0702:00:46
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17

EPSS

0.009

Percentile

82.7%

Tomcat Catalina is vulnerable to security constraint bypasses. If an error page is a static file, catalina is supposed to serve the content of the file as if processing a GET request, regardless of the HTTP method used. Catalina, however, did not do this. This leads to unexpected results for static error pages including the replacement or removal of custom error pages.

References