Moderate severityNVD Advisory· Published Aug 15, 2011· Updated Jun 16, 2026
CVE-2011-2481
CVE-2011-2481
Description
Apache Tomcat 7.0.x before 7.0.17 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application. NOTE: this vulnerability exists because of a CVE-2009-0783 regression.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.tomcat:tomcatMaven | >= 7.0.0, < 7.0.17 | 7.0.17 |
Affected products
17cpe:2.3:a:apache:tomcat:7.0.0:*:*:*:*:*:*:*+ 15 more
- cpe:2.3:a:apache:tomcat:7.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:7.0.0:beta:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:7.0.10:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:7.0.11:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:7.0.12:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:7.0.13:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:7.0.14:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:7.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:7.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:7.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:7.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:7.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:7.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:7.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:7.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:7.0.9:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
13- svn.apache.org/viewvcnvdPatchWEB
- svn.apache.org/viewvcnvdPatchWEB
- tomcat.apache.org/security-7.htmlnvdPatchVendor AdvisoryWEB
- issues.apache.org/bugzilla/show_bug.cginvdExploitWEB
- github.com/advisories/GHSA-r7c8-hghc-2mp8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2011-2481ghsaADVISORY
- marc.infonvdWEB
- github.com/apache/tomcat/commit/279e4451cb996f810fbca2f78b6340412d9daa7bghsaWEB
- web.archive.org/web/20111209022500/http://www.securityfocus.com/bid/49147ghsaWEB
- web.archive.org/web/20161127215021/http://securitytracker.com/idghsaWEB
- secunia.com/advisories/57126nvd
- securitytracker.com/idnvd
- www.securityfocus.com/bid/49147nvd
News mentions
0No linked articles in our index yet.