5

CVE-2011-2729

native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to an application.

Data is provided by the National Vulnerability Database (NVD)
ApacheTomcat Version5.5.32
   ApacheApache Commons Daemon Version1.0.3
   ApacheApache Commons Daemon Version1.0.4
   ApacheApache Commons Daemon Version1.0.5
   ApacheApache Commons Daemon Version1.0.6
   LinuxLinux Kernel
ApacheTomcat Version5.5.33
   ApacheApache Commons Daemon Version1.0.3
   ApacheApache Commons Daemon Version1.0.4
   ApacheApache Commons Daemon Version1.0.5
   ApacheApache Commons Daemon Version1.0.6
   LinuxLinux Kernel
ApacheTomcat Version6.0.30
   ApacheApache Commons Daemon Version1.0.3
   ApacheApache Commons Daemon Version1.0.4
   ApacheApache Commons Daemon Version1.0.5
   ApacheApache Commons Daemon Version1.0.6
   LinuxLinux Kernel
ApacheTomcat Version6.0.31
   ApacheApache Commons Daemon Version1.0.3
   ApacheApache Commons Daemon Version1.0.4
   ApacheApache Commons Daemon Version1.0.5
   ApacheApache Commons Daemon Version1.0.6
   LinuxLinux Kernel
ApacheTomcat Version6.0.32
   ApacheApache Commons Daemon Version1.0.3
   ApacheApache Commons Daemon Version1.0.4
   ApacheApache Commons Daemon Version1.0.5
   ApacheApache Commons Daemon Version1.0.6
   LinuxLinux Kernel
ApacheApache Commons Daemon Version1.0.3
   LinuxLinux Kernel
ApacheApache Commons Daemon Version1.0.4
   LinuxLinux Kernel
ApacheApache Commons Daemon Version1.0.5
   LinuxLinux Kernel
ApacheApache Commons Daemon Version1.0.6
   LinuxLinux Kernel
ApacheTomcat Version7.0.0
   LinuxLinux Kernel
ApacheTomcat Version7.0.0 Updatebeta
   LinuxLinux Kernel
ApacheTomcat Version7.0.1
   LinuxLinux Kernel
ApacheTomcat Version7.0.2
   LinuxLinux Kernel
ApacheTomcat Version7.0.3
   LinuxLinux Kernel
ApacheTomcat Version7.0.4
   LinuxLinux Kernel
ApacheTomcat Version7.0.5
   LinuxLinux Kernel
ApacheTomcat Version7.0.6
   LinuxLinux Kernel
ApacheTomcat Version7.0.7
   LinuxLinux Kernel
ApacheTomcat Version7.0.8
   LinuxLinux Kernel
ApacheTomcat Version7.0.9
   LinuxLinux Kernel
ApacheTomcat Version7.0.10
   LinuxLinux Kernel
ApacheTomcat Version7.0.11
   LinuxLinux Kernel
ApacheTomcat Version7.0.12
   LinuxLinux Kernel
ApacheTomcat Version7.0.13
   LinuxLinux Kernel
ApacheTomcat Version7.0.14
   LinuxLinux Kernel
ApacheTomcat Version7.0.16
   LinuxLinux Kernel
ApacheTomcat Version7.0.17
   LinuxLinux Kernel
ApacheTomcat Version7.0.19
   LinuxLinux Kernel
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 8.78% 0.916
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N