AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2010-3718

LOW · CVSS 1.2 EPSS 1.35%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2011-02-10 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2010-3718
Severity
LOW
CVSS
1.2
EPSS
1.35%
Apache

Original NVD Description

Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.