CVE-2013-0346

** DISPUTED ** Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might allow local users to obtain sensitive information by reading a file. NOTE: One Tomcat distributor has stated "The tomcat log directory does not contain any sensitive information."

Date published : 2014-02-15

https://bugzilla.redhat.com/show_bug.cgi?id=924841

http://www.openwall.com/lists/oss-security/2013/02/23/5