NVD

Id
15075  
Name
CVE-2010-3718  
Description
Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.  
Reject
 
CVSS Version
2  
CVSS Score
1.2  
Severity
Low  
CVSS Base Score
1.2  
CVSS Impact Subscore
2.9  
CVSS Exploit Subscore
1.9  
CVSS Vector
(AV:L/AC:H/Au:N/C:N/I:P/A:N)  
Pub Date
2017-01-18  
Published
2011-02-10  
Modified Date
2016-08-22  
Seq
2010-3718  

Actions