oval:org.mitre.oval:def:12701
Definition Id: oval:org.mitre.oval:def:12701 | |||
Oval ID: | oval:org.mitre.oval:def:12701 | ||
Title: | Security bypass vulnerability in Apache Tomcat 7.0.11 | ||
Description: | Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1088 and CVE-2011-1419. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2011-1183 | Version: | 3 |
Platform(s): | Microsoft Windows 2000 Microsoft Windows 7 Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Vista Microsoft Windows XP | Product(s): | Apache Tomcat |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:12401 | |||
Oval ID: | oval:org.mitre.oval:def:12401 | ||
Title: | Apache Tomcat is installed | ||
Description: | Apache Tomcat is installed | ||
Family: | windows | Class: | inventory |
Reference(s): | cpe:/a:apache:tomcat | Version: | 3 |
Platform(s): | Microsoft Windows 2000 Microsoft Windows 7 Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Vista Microsoft Windows XP | Product(s): | Apache Tomcat |
Definition Synopsis: | |||
Referenced By: | |||
oval:org.mitre.oval:def:12701 |