Back

LOW

tomcat: file permission bypass flaw

Published Feb 10, 2011

Description

Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (50)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 10, 2011
Updated Aug 7, 2024
Reserved Oct 1, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Feb 5, 2011
GHSA-FJ6C-PRGJ-GR3R