Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.apache.tomcat/tomcat
  4. ›
  5. CVE-2011-2481

CVE-2011-2481: File modification in Apache Tomcat

May 17, 2022 (updated February 14, 2023)

Apache Tomcat 7.0.x before 7.0.17 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application. NOTE: this vulnerability exists because of a CVE-2009-0783 regression.

References

  • marc.info/?l=bugtraq&m=139344343412337&w=2
  • secunia.com/advisories/57126
  • securitytracker.com/id?1025924
  • svn.apache.org/viewvc?view=revision&revision=1137753
  • svn.apache.org/viewvc?view=revision&revision=1138788
  • tomcat.apache.org/security-7.html
  • www.securityfocus.com/bid/49147
  • github.com/advisories/GHSA-r7c8-hghc-2mp8
  • issues.apache.org/bugzilla/show_bug.cgi?id=51395
  • nvd.nist.gov/vuln/detail/CVE-2011-2481

Code Behaviors & Features

Detect and mitigate CVE-2011-2481 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 7.0.0 before 7.0.17

Fixed versions

  • 7.0.17

Solution

Upgrade to version 7.0.17 or above.

Impact 4.6 MEDIUM

AV:L/AC:L/Au:N/C:P/I:P/A:P

Learn more about CVSS

Source file

maven/org.apache.tomcat/tomcat/CVE-2011-2481.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:16:08 +0000.