CVE-2011-3376

Publication date

2011-11-11 21:00:00

Family

redhat

State

PUBLISHED

Description

org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local users to gain privileges by using an untrusted web application to access the Manager applications functionality.