Description
A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via manipulation of the configuration parameters for the JSP Servlet.
Remediation
References
Related Vulnerabilities
WordPress Plugin Tajer Arbitrary File Upload (1.0.5)
WebLogic CVE-2022-21557 Vulnerability (CVE-2022-21557)
WordPress 3.8.x Same Origin Method Execution (SOME) Vulnerability (3.8 - 3.8.13)
Jboss EAP Deserialization of Untrusted Data Vulnerability (CVE-2019-16942)
WordPress 4.5.x Arbitrary File Deletion Vulnerability (4.5 - 4.5.14)