Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 were only applied once a Servlet had been loaded. Because security constraints defined in this way apply to the URL pattern and any URLs below that point, it was possible - depending on the order Servlets were loaded - for some security constraints not to be applied. This could have exposed resources to users who were not authorised to access them.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Tomcat | Apache | 7.0.0 (including) | 7.0.84 (including) |
Red Hat Enterprise Linux 7 | RedHat | tomcat-0:7.0.76-9.el7 | * |
Red Hat Fuse Intergration Services 2.0 based on Fuse 6.3 R8 | RedHat | * | |
Red Hat JBoss Web Server 3.1 | RedHat | * | |
Red Hat JBoss Web Server 3 for RHEL 6 | RedHat | mod_cluster-0:1.3.8-2.Final_redhat_2.1.ep7.el6 | * |
Red Hat JBoss Web Server 3 for RHEL 6 | RedHat | tomcat7-0:7.0.70-25.ep7.el6 | * |
Red Hat JBoss Web Server 3 for RHEL 6 | RedHat | tomcat8-0:8.0.36-29.ep7.el6 | * |
Red Hat JBoss Web Server 3 for RHEL 6 | RedHat | tomcat-native-0:1.2.8-11.redhat_11.ep7.el6 | * |
Red Hat JBoss Web Server 3 for RHEL 6 | RedHat | tomcat-vault-0:1.1.6-1.Final_redhat_1.1.ep7.el6 | * |
Red Hat JBoss Web Server 3 for RHEL 7 | RedHat | mod_cluster-0:1.3.8-2.Final_redhat_2.1.ep7.el7 | * |
Red Hat JBoss Web Server 3 for RHEL 7 | RedHat | tomcat7-0:7.0.70-25.ep7.el7 | * |
Red Hat JBoss Web Server 3 for RHEL 7 | RedHat | tomcat8-0:8.0.36-29.ep7.el7 | * |
Red Hat JBoss Web Server 3 for RHEL 7 | RedHat | tomcat-native-0:1.2.8-11.redhat_11.ep7.el7 | * |
Red Hat JBoss Web Server 3 for RHEL 7 | RedHat | tomcat-vault-0:1.1.6-1.Final_redhat_1.1.ep7.el7 | * |
Red Hat Openshift Application Runtimes | RedHat | * | |
Tomcat7 | Ubuntu | esm-apps/xenial | * |
Tomcat7 | Ubuntu | trusty | * |
Tomcat7 | Ubuntu | upstream | * |
Tomcat7 | Ubuntu | xenial | * |
Tomcat8 | Ubuntu | artful | * |
Tomcat8 | Ubuntu | upstream | * |
Tomcat8 | Ubuntu | xenial | * |
Tomcat8.0 | Ubuntu | artful | * |