5

CVE-2011-2729

native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to an application.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheTomcat Version5.5.32
   ApacheApache Commons Daemon Version1.0.3
   ApacheApache Commons Daemon Version1.0.4
   ApacheApache Commons Daemon Version1.0.5
   ApacheApache Commons Daemon Version1.0.6
   LinuxLinux Kernel
ApacheTomcat Version5.5.33
   ApacheApache Commons Daemon Version1.0.3
   ApacheApache Commons Daemon Version1.0.4
   ApacheApache Commons Daemon Version1.0.5
   ApacheApache Commons Daemon Version1.0.6
   LinuxLinux Kernel
ApacheTomcat Version6.0.30
   ApacheApache Commons Daemon Version1.0.3
   ApacheApache Commons Daemon Version1.0.4
   ApacheApache Commons Daemon Version1.0.5
   ApacheApache Commons Daemon Version1.0.6
   LinuxLinux Kernel
ApacheTomcat Version6.0.31
   ApacheApache Commons Daemon Version1.0.3
   ApacheApache Commons Daemon Version1.0.4
   ApacheApache Commons Daemon Version1.0.5
   ApacheApache Commons Daemon Version1.0.6
   LinuxLinux Kernel
ApacheTomcat Version6.0.32
   ApacheApache Commons Daemon Version1.0.3
   ApacheApache Commons Daemon Version1.0.4
   ApacheApache Commons Daemon Version1.0.5
   ApacheApache Commons Daemon Version1.0.6
   LinuxLinux Kernel
ApacheApache Commons Daemon Version1.0.3
   LinuxLinux Kernel
ApacheApache Commons Daemon Version1.0.4
   LinuxLinux Kernel
ApacheApache Commons Daemon Version1.0.5
   LinuxLinux Kernel
ApacheApache Commons Daemon Version1.0.6
   LinuxLinux Kernel
ApacheTomcat Version7.0.0
   LinuxLinux Kernel
ApacheTomcat Version7.0.0 Updatebeta
   LinuxLinux Kernel
ApacheTomcat Version7.0.1
   LinuxLinux Kernel
ApacheTomcat Version7.0.2
   LinuxLinux Kernel
ApacheTomcat Version7.0.3
   LinuxLinux Kernel
ApacheTomcat Version7.0.4
   LinuxLinux Kernel
ApacheTomcat Version7.0.5
   LinuxLinux Kernel
ApacheTomcat Version7.0.6
   LinuxLinux Kernel
ApacheTomcat Version7.0.7
   LinuxLinux Kernel
ApacheTomcat Version7.0.8
   LinuxLinux Kernel
ApacheTomcat Version7.0.9
   LinuxLinux Kernel
ApacheTomcat Version7.0.10
   LinuxLinux Kernel
ApacheTomcat Version7.0.11
   LinuxLinux Kernel
ApacheTomcat Version7.0.12
   LinuxLinux Kernel
ApacheTomcat Version7.0.13
   LinuxLinux Kernel
ApacheTomcat Version7.0.14
   LinuxLinux Kernel
ApacheTomcat Version7.0.16
   LinuxLinux Kernel
ApacheTomcat Version7.0.17
   LinuxLinux Kernel
ApacheTomcat Version7.0.19
   LinuxLinux Kernel
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.78% 0.916
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N