CVE Vulnerabilities

CVE-2009-2901

Published: Jan 28, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The autodeployment process in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20, when autoDeploy is enabled, deploys appBase files that remain from a failed undeploy, which might allow remote attackers to bypass intended authentication requirements via HTTP requests.

Affected Software

NameVendorStart VersionEnd Version
TomcatApache5.5.0 (including)5.5.0 (including)
TomcatApache5.5.1 (including)5.5.1 (including)
TomcatApache5.5.2 (including)5.5.2 (including)
TomcatApache5.5.3 (including)5.5.3 (including)
TomcatApache5.5.4 (including)5.5.4 (including)
TomcatApache5.5.5 (including)5.5.5 (including)
TomcatApache5.5.6 (including)5.5.6 (including)
TomcatApache5.5.7 (including)5.5.7 (including)
TomcatApache5.5.8 (including)5.5.8 (including)
TomcatApache5.5.9 (including)5.5.9 (including)
TomcatApache5.5.10 (including)5.5.10 (including)
TomcatApache5.5.11 (including)5.5.11 (including)
TomcatApache5.5.12 (including)5.5.12 (including)
TomcatApache5.5.13 (including)5.5.13 (including)
TomcatApache5.5.14 (including)5.5.14 (including)
TomcatApache5.5.15 (including)5.5.15 (including)
TomcatApache5.5.16 (including)5.5.16 (including)
TomcatApache5.5.17 (including)5.5.17 (including)
TomcatApache5.5.18 (including)5.5.18 (including)
TomcatApache5.5.19 (including)5.5.19 (including)
TomcatApache5.5.20 (including)5.5.20 (including)
TomcatApache5.5.21 (including)5.5.21 (including)
TomcatApache5.5.22 (including)5.5.22 (including)
TomcatApache5.5.23 (including)5.5.23 (including)
TomcatApache5.5.24 (including)5.5.24 (including)
TomcatApache5.5.25 (including)5.5.25 (including)
TomcatApache5.5.26 (including)5.5.26 (including)
TomcatApache5.5.27 (including)5.5.27 (including)
TomcatApache5.5.28 (including)5.5.28 (including)
TomcatApache6.0 (including)6.0 (including)
TomcatApache6.0.0 (including)6.0.0 (including)
TomcatApache6.0.1 (including)6.0.1 (including)
TomcatApache6.0.2 (including)6.0.2 (including)
TomcatApache6.0.3 (including)6.0.3 (including)
TomcatApache6.0.4 (including)6.0.4 (including)
TomcatApache6.0.5 (including)6.0.5 (including)
TomcatApache6.0.6 (including)6.0.6 (including)
TomcatApache6.0.7 (including)6.0.7 (including)
TomcatApache6.0.8 (including)6.0.8 (including)
TomcatApache6.0.9 (including)6.0.9 (including)
TomcatApache6.0.10 (including)6.0.10 (including)
TomcatApache6.0.11 (including)6.0.11 (including)
TomcatApache6.0.12 (including)6.0.12 (including)
TomcatApache6.0.13 (including)6.0.13 (including)
TomcatApache6.0.14 (including)6.0.14 (including)
TomcatApache6.0.15 (including)6.0.15 (including)
TomcatApache6.0.16 (including)6.0.16 (including)
TomcatApache6.0.17 (including)6.0.17 (including)
TomcatApache6.0.18 (including)6.0.18 (including)
TomcatApache6.0.19 (including)6.0.19 (including)
TomcatApache6.0.20 (including)6.0.20 (including)
Tomcat5Ubuntudapper*
Tomcat5.5Ubuntuhardy*
Tomcat5.5Ubuntuintrepid*
Tomcat5.5Ubuntujaunty*
Tomcat6Ubuntuintrepid*
Tomcat6Ubuntujaunty*
Tomcat6Ubuntukarmic*

References