Looking for the vulnerability index of Invicti's legacy products?
Apache Tomcat Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-3376) - Vulnerability Database

Apache Tomcat Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-3376)

Description

org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local users to gain privileges by using an untrusted web application to access the Manager application's functionality.

References