Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-2204

Опубликовано: 27 июн. 2011
Источник: redhat
CVSS2: 2.1

Описание

Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.17, when the MemoryUserDatabase is used, creates log entries containing passwords upon encountering errors in JMX user creation, which allows local users to obtain sensitive information by reading a log file.

Отчет

The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw.

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=717013tomcat: password disclosure vulnerability

2.1 Low

CVSS2

Связанные уязвимости

ubuntu
больше 14 лет назад

Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.17, when the MemoryUserDatabase is used, creates log entries containing passwords upon encountering errors in JMX user creation, which allows local users to obtain sensitive information by reading a log file.

nvd
больше 14 лет назад

Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.17, when the MemoryUserDatabase is used, creates log entries containing passwords upon encountering errors in JMX user creation, which allows local users to obtain sensitive information by reading a log file.

debian
больше 14 лет назад

Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7 ...

github
больше 3 лет назад

Insertion of Sensitive Information into Log File in Apache Tomcat

oracle-oval
почти 14 лет назад

ELSA-2011-1845: tomcat5 security update (MODERATE)

2.1 Low

CVSS2