Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:5851
HistoryFeb 27, 2018 - 1:21 a.m.

Security Constraint Bypass

2018-02-2701:21:00
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15

0.001 Low

EPSS

Percentile

44.6%

tomcat-catalina is vulnerable to security constraint bypass. Security constraints are only applied after a servlet has already been loaded. Depending on the order in which the servlets were loaded, its possible that some of the constraints were not applied at all. Leveraging this, users may have access to exposed resources which they would not ordinarily have access to.

References