Description
Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1088 and CVE-2011-1419.
Remediation
References
Related Vulnerabilities
Liferay DXP Insufficient Session Expiration Vulnerability (CVE-2025-43819)
OpenSSL Out-of-bounds Read Vulnerability (CVE-2022-4203)
YOURLS Access of Resource Using Incompatible Type ('Type Confusion') Vulnerability (CVE-2019-14537)
MySQL CVE-2019-2802 Vulnerability (CVE-2019-2802)
Jboss EAP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-9788)