Apache Tomcat 7.x < 7.0.4 SecurityManager Local Security Bypass
Medium Nessus Plugin ID 51958
SynopsisThe remote web server is affected by a security bypass vulnerability.
DescriptionAccording to its self-reported version number, the instance of Apache Tomcat 7.x listening on the remote host is prior to 7.0.4. It is, therefore, affected by a security bypass vulnerability due to an error in the access restriction on a 'ServletContext' attribute which holds the location of the work directory in Tomcat's SecurityManager. A malicious web application can modify the location of the working directory which then allows improper read and write access to arbitrary files and directories in the context of Tomcat.
Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
SolutionUpgrade to Apache Tomcat version 7.0.4 or later. Alternatively, undeploy untrusted third-party web applications.