CVE-2011-1088
Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application.
Date published : 2011-03-14
http://www.securityfocus.com/bid/46685
http://www.securityfocus.com/archive/1/517013/100/0/threaded
