CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 4.4. It affects Apache, Java.
CVE
CVE-2011-3376
Severity
MEDIUM
CVSS
4.4
EPSS
0.64%
Apache Java
Original NVD Description
org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local users to gain privileges by using an untrusted web application to access the Manager application's functionality.