Description
Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application.
Mitigation
We recommend upgrading to a version of this component that is not vulnerable to this specific issue. While this CVE is partially fixed in version 7.0.10, the vulnerability is ultimately fixed in 7.0.11 with CVE-2011-1419.