Affected Versions:
Apache Group Tomcat 7.x
Vulnerability description:
Apache Tomcat is a popular open source JSP application server program.
The "@ ServletSecurity" annotation security restriction bypass vulnerability exists in Apache Tomcat implementation. Remote attackers can exploit this vulnerability to bypass certain security restrictions.
Because the application fails to correctly execute the "@ ServletSecurity" comment when loading the small service program, you can bypass the specified security restriction and expose some information.
<* Reference
Http://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.10_%28released_8_Mar_2011%29
*>
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Html> http://jakarta.apache.org/tomcat/index.html