Description
Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088.
Remediation
References
Related Vulnerabilities
Jboss EAP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-4112)
Oracle JRE CVE-2019-2949 Vulnerability (CVE-2019-2949)
PostgreSQL Incorrect Ownership Assignment Vulnerability (CVE-2026-6469)
SharePoint Out-of-bounds Read Vulnerability (CVE-2026-55050)
WordPress Plugin Category Specific RSS feed Subscription Cross-Site Request Forgery (2.0)