The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain permissions for web applications, which allows attackers to modify logging configuration options and overwrite arbitrary files, as demonstrated by changing the (1) level, (2) directory, and (3) prefix attributes in the org.apache.juli.FileHandler handler.
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00460.html
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00315.html
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10417
https://exchange.xforce.ibmcloud.com/vulnerabilities/39201
http://www.vupen.com/english/advisories/2009/3316
http://www.vupen.com/english/advisories/2008/2823
http://www.vupen.com/english/advisories/2008/2780
http://www.vupen.com/english/advisories/2008/1856/references
http://www.vupen.com/english/advisories/2008/0013
http://www.vmware.com/security/advisories/VMSA-2009-0016.html
http://www.vmware.com/security/advisories/VMSA-2008-0010.html
http://www.securityfocus.com/bid/31681
http://www.securityfocus.com/bid/27006
http://www.securityfocus.com/archive/1/507985/100/0/threaded
http://www.securityfocus.com/archive/1/485481/100/0/threaded
http://www.redhat.com/support/errata/RHSA-2008-0862.html
http://www.redhat.com/support/errata/RHSA-2008-0834.html
http://www.redhat.com/support/errata/RHSA-2008-0833.html
http://www.redhat.com/support/errata/RHSA-2008-0832.html
http://www.redhat.com/support/errata/RHSA-2008-0831.html
http://www.redhat.com/support/errata/RHSA-2008-0195.html
http://www.redhat.com/support/errata/RHSA-2008-0042.html
http://www.mandriva.com/security/advisories?name=MDVSA-2008:188
http://www.debian.org/security/2008/dsa-1447
http://tomcat.apache.org/security-6.html
http://tomcat.apache.org/security-5.html
http://svn.apache.org/viewvc?view=rev&revision=606594
http://support.avaya.com/elmodocs2/security/ASA-2008-401.htm
http://support.apple.com/kb/HT3216
http://securityreason.com/securityalert/3485
http://security.gentoo.org/glsa/glsa-200804-10.xml
http://secunia.com/advisories/57126
http://secunia.com/advisories/37460
http://secunia.com/advisories/32266
http://secunia.com/advisories/32222
http://secunia.com/advisories/32120
http://secunia.com/advisories/30676
http://secunia.com/advisories/29711
http://secunia.com/advisories/29313
http://secunia.com/advisories/28915
http://secunia.com/advisories/28317
http://secunia.com/advisories/28274
http://marc.info/?l=bugtraq&m=139344343412337&w=2
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html
http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html