CVE-2011-1088

EPSS 16.4%

Apache Tomcat allows remote attackers to bypass intended access restrictions

Published: 5/14/2022Modified: 2/27/2024

Description

Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application.

Affected packages (1)

References (37)