Apache Tomcat Other Vulnerability - CVE-2011-1419 - Vulnerability Database

Apache Tomcat Other Vulnerability - CVE-2011-1419

Medium
Reference: CVE-2011-1419
Title: Apache Tomcat Other Vulnerability
Overview:

Apache Tomcat 7.x before 7.0.11 when web.xml has no security constraints does not follow ServletSecurity annotations which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088.