Release date: 2011-11-09
Updated on: 2011-11-10
Affected Systems:
Apache Group Tomcat 7.x
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2011-3376
Tomcat is a Servlet container developed by the Jakarta project under the Apache Software Foundation. According to the technical specifications provided by Sun Microsystems, Tomcat supports Servlet and JavaServer Page (JSP, it also provides some special functions as Web servers, such as Tomcat Management and Control Platform, security domain management, and Tomcat valve.
Apache Tomcat has security vulnerabilities. Suspicious Web applications can access and manage applications, and malicious users can bypass certain security restrictions. The "manager-script" permission is required for successful exploitation.
<* Source: Ate Douma
Link: http://tomcat.apache.org/security-7.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://jakarta.apache.org/tomcat/index.html