CVE-2011-1088
Apache Tomcat allows remote attackers to bypass intended access restrictions
EPSS 16.4%
Description
Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application.
How to fix CVE-2011-1088
To remediate CVE-2011-1088, upgrade the affected package to a fixed version below.
- Maven/org.apache.tomcat:tomcat—upgrade to 7.0.10 or later
Is CVE-2011-1088 being exploited?
Moderate — EPSS is 16.4%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- >= 7.0.0, < 7.0.10