Логотип exploitDog
product: "tomcat"
Консоль
Логотип exploitDog

exploitDog

product: "tomcat"
Tomcat

Tomcatконтейнер сервлетов с открытым исходным кодом

Релизный цикл, информация об уязвимостях

Продукт: Tomcat
Вендор: apache

График релизов

8.08.5910.010.111.020142015201620172018201920202021202220232024202520262027

Недавние уязвимости Tomcat

Количество 1 262

nvd логотип

CVE-2011-5064

около 14 лет назад

DigestAuthenticator.java in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 uses Catalina as the hard-coded server secret (aka private key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging knowledge of this string, a different vulnerability than CVE-2011-1184.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2011-5064

около 14 лет назад

DigestAuthenticator.java in the HTTP Digest Access Authentication impl ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-5063

около 14 лет назад

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check realm values, which might allow remote attackers to bypass intended access restrictions by leveraging the availability of a protection space with weaker authentication or authorization requirements, a different vulnerability than CVE-2011-1184.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2011-5063

около 14 лет назад

The HTTP Digest Access Authentication implementation in Apache Tomcat ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-5062

около 14 лет назад

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qop values, which might allow remote attackers to bypass intended integrity-protection requirements via a qop=auth value, a different vulnerability than CVE-2011-1184.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2011-5062

около 14 лет назад

The HTTP Digest Access Authentication implementation in Apache Tomcat ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2011-1184

около 14 лет назад

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not have the expected countermeasures against replay attacks, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, related to lack of checking of nonce (aka server nonce) and nc (aka nonce-count or client nonce count) values.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2011-1184

около 14 лет назад

The HTTP Digest Access Authentication implementation in Apache Tomcat ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-5064

около 14 лет назад

DigestAuthenticator.java in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 uses Catalina as the hard-coded server secret (aka private key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging knowledge of this string, a different vulnerability than CVE-2011-1184.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2011-5062

около 14 лет назад

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qop values, which might allow remote attackers to bypass intended integrity-protection requirements via a qop=auth value, a different vulnerability than CVE-2011-1184.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2011-5064

DigestAuthenticator.java in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 uses Catalina as the hard-coded server secret (aka private key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging knowledge of this string, a different vulnerability than CVE-2011-1184.

CVSS2: 4.3
5%
Низкий
около 14 лет назад
debian логотип
CVE-2011-5064

DigestAuthenticator.java in the HTTP Digest Access Authentication impl ...

CVSS2: 4.3
5%
Низкий
около 14 лет назад
nvd логотип
CVE-2011-5063

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check realm values, which might allow remote attackers to bypass intended access restrictions by leveraging the availability of a protection space with weaker authentication or authorization requirements, a different vulnerability than CVE-2011-1184.

CVSS2: 4.3
2%
Низкий
около 14 лет назад
debian логотип
CVE-2011-5063

The HTTP Digest Access Authentication implementation in Apache Tomcat ...

CVSS2: 4.3
2%
Низкий
около 14 лет назад
nvd логотип
CVE-2011-5062

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qop values, which might allow remote attackers to bypass intended integrity-protection requirements via a qop=auth value, a different vulnerability than CVE-2011-1184.

CVSS2: 5
3%
Низкий
около 14 лет назад
debian логотип
CVE-2011-5062

The HTTP Digest Access Authentication implementation in Apache Tomcat ...

CVSS2: 5
3%
Низкий
около 14 лет назад
nvd логотип
CVE-2011-1184

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not have the expected countermeasures against replay attacks, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, related to lack of checking of nonce (aka server nonce) and nc (aka nonce-count or client nonce count) values.

CVSS2: 5
7%
Низкий
около 14 лет назад
debian логотип
CVE-2011-1184

The HTTP Digest Access Authentication implementation in Apache Tomcat ...

CVSS2: 5
7%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2011-5064

DigestAuthenticator.java in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 uses Catalina as the hard-coded server secret (aka private key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging knowledge of this string, a different vulnerability than CVE-2011-1184.

CVSS2: 4.3
5%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2011-5062

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qop values, which might allow remote attackers to bypass intended integrity-protection requirements via a qop=auth value, a different vulnerability than CVE-2011-1184.

CVSS2: 5
3%
Низкий
около 14 лет назад

Уязвимостей на страницу


Поделиться