Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2011-2204

Опубликовано: 29 июн. 2011
Источник: debian
EPSS Низкий

Описание

Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.17, when the MemoryUserDatabase is used, creates log entries containing passwords upon encountering errors in JMX user creation, which allows local users to obtain sensitive information by reading a log file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tomcat5.5removedpackage
tomcat5.5no-dsalennypackage
tomcat6fixed6.0.32-5package
tomcat6no-dsalennypackage
tomcat6no-dsasqueezepackage
tomcat7fixed7.0.16-3package

EPSS

Процентиль: 23%
0.00074
Низкий

Связанные уязвимости

ubuntu
почти 14 лет назад

Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.17, when the MemoryUserDatabase is used, creates log entries containing passwords upon encountering errors in JMX user creation, which allows local users to obtain sensitive information by reading a log file.

redhat
почти 14 лет назад

Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.17, when the MemoryUserDatabase is used, creates log entries containing passwords upon encountering errors in JMX user creation, which allows local users to obtain sensitive information by reading a log file.

nvd
почти 14 лет назад

Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.17, when the MemoryUserDatabase is used, creates log entries containing passwords upon encountering errors in JMX user creation, which allows local users to obtain sensitive information by reading a log file.

github
около 3 лет назад

Insertion of Sensitive Information into Log File in Apache Tomcat

oracle-oval
больше 13 лет назад

ELSA-2011-1845: tomcat5 security update (MODERATE)

EPSS

Процентиль: 23%
0.00074
Низкий