Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The autodeployment process in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20, when autoDeploy is enabled, deploys appBase files that remain from a failed undeploy, which might allow remote attackers to bypass intended authentication requirements via HTTP requests.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apache Tomcat 权限许可和访问控制问题漏洞
Vulnerability Description
Apache Tomcat是一个流行的开放源码的JSP应用服务器程序。 默认下Tomcat会自动部署主机appBase中的任何目录,这种行为是受主机的autoDeploy属性(默认为true)控制的。如果卸载部署失败,自动部署过程仍会部署剩余的文件,导致正常情况下受一个或多个安全限制保护的文件也被继续部署,这样用户就可无需认证便访问这些文件。
CVSS Information
N/A
Vulnerability Type
N/A