Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:5856
HistoryFeb 27, 2018 - 5:36 a.m.

Authorization Bypass

2018-02-2705:36:11
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.002 Low

EPSS

Percentile

64.5%

tomcat-catalina is vulnerable to authorization bypass. URL patterns of empty strings were not handled correctly and caused the server to ignore such security constraints when the urlPattern for a servlet is mapped to " ". This allows an attacker to bypass said security constraints and gain unauthorized access to server resources.

References