CVE-2011-2481
Estado: ModificadaMedia (4.6)—
Apache Tomcat 7.0.x before 7.0.17 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application. NOTE: this vulnerability exists because of a CVE-2009-0783 regression.
CVSS
- Versión: 2.0
- Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 4.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.84%
- Percentil entre todas las CVEs puntuadas: 57
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://marc.info/?l=bugtraq&m=139344343412337&w=2
- http://secunia.com/advisories/57126
- http://securitytracker.com/id?1025924
- http://svn.apache.org/viewvc?view=revision&revision=1137753
- http://svn.apache.org/viewvc?view=revision&revision=1138788
- http://tomcat.apache.org/security-7.html
- http://www.securityfocus.com/bid/49147
- https://issues.apache.org/bugzilla/show_bug.cgi?id=51395
- http://marc.info/?l=bugtraq&m=139344343412337&w=2
- http://secunia.com/advisories/57126
- http://securitytracker.com/id?1025924
- http://svn.apache.org/viewvc?view=revision&revision=1137753
- http://svn.apache.org/viewvc?view=revision&revision=1138788
- http://tomcat.apache.org/security-7.html
- http://www.securityfocus.com/bid/49147
- https://issues.apache.org/bugzilla/show_bug.cgi?id=51395
JSON original (NVD)
Mostrar
{
"id": "CVE-2011-2481",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.6,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2011-08-15T21:55:01.910",
"references": [
{
"url": "http://marc.info/?l=bugtraq&m=139344343412337&w=2",
"source": "secalert@redhat.com"
},
{
"url": "http://secunia.com/advisories/57126",
"source": "secalert@redhat.com"
},
{
"url": "http://securitytracker.com/id?1025924",
"source": "secalert@redhat.com"
},
{
"url": "http://svn.apache.org/viewvc?view=revision&revision=1137753",
"tags": [
"Patch"
],
"source": "secalert@redhat.com"
},
{
"url": "http://svn.apache.org/viewvc?view=revision&revision=1138788",
"tags": [
"Patch"
],
"source": "secalert@redhat.com"
},
{
"url": "http://tomcat.apache.org/security-7.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://www.securityfocus.com/bid/49147",
"source": "secalert@redhat.com"
},
{
"url": "https://issues.apache.org/bugzilla/show_bug.cgi?id=51395",
"tags": [
"Exploit"
],
"source": "secalert@redhat.com"
},
{
"url": "http://marc.info/?l=bugtraq&m=139344343412337&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/57126",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securitytracker.com/id?1025924",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://svn.apache.org/viewvc?view=revision&revision=1137753",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://svn.apache.org/viewvc?view=revision&revision=1138788",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://tomcat.apache.org/security-7.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/49147",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://issues.apache.org/bugzilla/show_bug.cgi?id=51395",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Apache Tomcat 7.0.x before 7.0.17 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application. NOTE: this vulnerability exists because of a CVE-2009-0783 regression."
},
{
"lang": "es",
"value": "Apache Tomcat v7.0.x anterior a v7.0.17 permite a aplicaciones web reemplazar un parseador XML usado por otras aplicaciones web, lo que permite a usuarios locales leer o modificar (1) web.xml, (2) context.xml, o (3) ficheros tld de aplicaciones de su elección a través de una aplicación manipulada cargada anteriormente de la aplicación objetivo. NOTA: esta vulnerabilidad existe debido a un regresión de CVE-2009-0783"
}
],
"lastModified": "2026-06-16T23:31:25.447",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0F8C62EF-1B67-456A-9C66-755439CF8556"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.0:beta:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "33E9607B-4D28-460D-896B-E4B7FA22441E"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A819E245-D641-4F19-9139-6C940504F6E7"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8C381275-10C5-4939-BCE3-0D1F3B3CB2EE"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7205475A-6D04-4042-B24E-1DA5A57029B7"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "08022987-B36B-4F63-88A5-A8F59195DF4A"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FF4B7557-EF35-451E-B55D-3296966695AC"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8980E61E-27BE-4858-82B3-C0E8128AF521"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8756BF9B-3E24-4677-87AE-31CE776541F0"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "88CE057E-2092-4C98-8D0C-75CF439D0A9C"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8F194580-EE6D-4E38-87F3-F0661262256B"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A9731BAA-4C6C-4259-B786-F577D8A90FA1"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.11:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1F74A421-D019-4248-84B8-C70D4D9A8A95"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.12:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2BA27FF9-4C66-4E17-95C0-1CB2DAA6AFC8"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.13:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "05346F5A-FB52-4376-AAC7-9A5308216545"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.14:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "305688F2-50A6-41FB-8614-BC589DB9A789"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com"
}