Privilege Escalation via Unrestricted ContainerServlets in Apache Tomcat 7.x

Privilege Escalation via Unrestricted ContainerServlets in Apache Tomcat 7.x

CVE-2011-3376 · MEDIUM Severity

AV:L/AC:M/AU:N/C:P/I:P/A:P

org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local users to gain privileges by using an untrusted web application to access the Manager application's functionality.

Learn more about our Cis Benchmark Audit For Apache Http Server.