CVE Identifier: CVE-2011-1183 Severity: Important Vendor: The Apache Software Foundation Versions Affected: - Tomcat 7.0.11 - Earlier versions are not affected Description: A regression in the fix for CVE-2011-1088 resulted in security constraints being ignored when no login configuration was present in the and the web application was marked as meta-data complete. Mitigation: - Upgrade to Tomcat 7.0.12 or later - Ensure a login configuration is defined in Credit: This issue was identified by the Apache Tomcat security team. References: - http://tomcat.apache.org/security.html - http://tomcat.apache.org/security-7.html