Apache Tomcat Other Vulnerability - CVE-2010-3718 - Vulnerability Database

Apache Tomcat Other Vulnerability - CVE-2010-3718

Low
Reference: CVE-2010-3718
Title: Apache Tomcat Other Vulnerability
Overview:

Apache Tomcat 7.0.0 through 7.0.3 6.0.x and 5.5.x when running within a SecurityManager does not make the ServletContext attribute read-only which allows local web applications to read or write files outside of the intended working directory as demonstrated using a directory traversal attack.