CERT-In Advisory
CIAD-2011-0063
Apache Tomcat Manager Application Servlets Security Bypass Vulnerability
Original Issue Date: November 16, 2011
Severity Rating: Medium
Systems Affected
- Apache Tomcat 7.0.0-7.0.21
Overview
A vulnerability has been reported in Apache Tomcat, which could allow a malicious users to bypass certain security restrictions.
Description
The vulnerability occurs when the access to the manager application servlets not being restricted from untrusted web applications which could allowed an untrusted web application to use the functionality of the Manager application. This could be used to obtain information on running web applications as well as deploying additional web applications.
Solution
Update to version 7.0.22.
http://svn.apache.org/viewvc/tomcat/tc7.0.x/trunk/java/org/apache/catalina/core/DefaultInstanceManager.java?r1=1176588&r2=1176587&pathrev=1176588
Vendor Information
Apache
http://tomcat.apache.org/security-7.html
References
Apache
http://tomcat.apache.org/security-7.html
Secunia
http://secunia.com/advisories/46733/
CVE Name
CVE-2011-3376
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|