Back

MEDIUM

Apache Tomcat CVE-2009-0783 regression

Published Aug 15, 2011

Description

Apache Tomcat 7.0.x before 7.0.17 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application. NOTE: this vulnerability exists because of a CVE-2009-0783 regression.

Affected products

Remediation

Red Hat statement

This issue did not affect any version of Tomcat shipped in Red Hat products. This flaw only affected Tomcat versions 7.0.0 - 7.0.16.

Metrics

References (16)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 15, 2011
Updated Aug 6, 2024
Reserved Jun 15, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Aug 12, 2011
GHSA-R7C8-HGHC-2MP8