Vulnerabilities > Apache > Tomcat > 7.0.18

DATE CVE VULNERABILITY TITLE RISK
2011-11-11 CVE-2011-3376 Permissions, Privileges, and Access Controls vulnerability in Apache Tomcat
org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local users to gain privileges by using an untrusted web application to access the Manager application's functionality.
local
apache CWE-264
4.4