CVE-2011-1582

medium
Published 2011-05-20 · Modified 2024-02-21
CVSS v3
CVSS v2
4.3
VIR risk
4.3

Description

Access restriction bypass in Apache Tomcat

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.vupen.com/english/advisories/2011/1255

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.securityfocus.com/bid/47886

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.14_%28released_12_May_2011%29

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://svn.apache.org/viewvc?view=revision&revision=1100832

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.apache.tomcat:tomcat>=7.0.12,<7.0.147.0.14

Application impact

VendorProductVersionsFixed
apache apachetomcat7.0.12
apache apachetomcat7.0.13

References

CWEs

CWE-264

Verify integrity in audit chain (admin only). AS-IS.