CVE Database
/

CVE-2011-2481

Back to search

CVE-2011-2481

Published: Aug 15, 2011

Modified: Aug 6, 2024

PUBLISHED

Description

Apache Tomcat 7.0.x before 7.0.17 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application. NOTE: this vulnerability exists because of a CVE-2009-0783 regression.

VendorProductVersions

n/a

n/a

affected
n/a

References

1025924
vdb-entry
x_refsource_SECTRACK
57126
third-party-advisory
x_refsource_SECUNIA
49147
vdb-entry
x_refsource_BID
HPSBST02955
vendor-advisory
x_refsource_HP

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now