CVE-2009-2901
Publication date 28 January 2010
Last updated 24 July 2024
Ubuntu priority
The autodeployment process in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20, when autoDeploy is enabled, deploys appBase files that remain from a failed undeploy, which might allow remote attackers to bypass intended authentication requirements via HTTP requests.
Status
Package | Ubuntu Release | Status |
---|---|---|
tomcat5 | ||
tomcat5.5 | ||
tomcat6 | ||
Patch details
Package | Patch details |
---|---|
tomcat5.5 | |
tomcat6 |
References
Related Ubuntu Security Notices (USN)
- USN-899-1
- Tomcat vulnerabilities
- 11 February 2010