Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-2204

Опубликовано: 27 июн. 2011
Источник: redhat
CVSS2: 2.1
EPSS Низкий

Описание

Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.17, when the MemoryUserDatabase is used, creates log entries containing passwords upon encountering errors in JMX user creation, which allows local users to obtain sensitive information by reading a log file.

Отчет

The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw.

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=717013tomcat: password disclosure vulnerability

EPSS

Процентиль: 23%
0.00074
Низкий

2.1 Low

CVSS2

Связанные уязвимости

ubuntu
почти 14 лет назад

Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.17, when the MemoryUserDatabase is used, creates log entries containing passwords upon encountering errors in JMX user creation, which allows local users to obtain sensitive information by reading a log file.

nvd
почти 14 лет назад

Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.17, when the MemoryUserDatabase is used, creates log entries containing passwords upon encountering errors in JMX user creation, which allows local users to obtain sensitive information by reading a log file.

debian
почти 14 лет назад

Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7 ...

github
около 3 лет назад

Insertion of Sensitive Information into Log File in Apache Tomcat

oracle-oval
больше 13 лет назад

ELSA-2011-1845: tomcat5 security update (MODERATE)

EPSS

Процентиль: 23%
0.00074
Низкий

2.1 Low

CVSS2