Количество 7
Количество 7
GHSA-4f7h-9j2x-cmr4
Improper Authentication in Apache Tomcat

CVE-2011-5062
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qop values, which might allow remote attackers to bypass intended integrity-protection requirements via a qop=auth value, a different vulnerability than CVE-2011-1184.

CVE-2011-5062
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qop values, which might allow remote attackers to bypass intended integrity-protection requirements via a qop=auth value, a different vulnerability than CVE-2011-1184.

CVE-2011-5062
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qop values, which might allow remote attackers to bypass intended integrity-protection requirements via a qop=auth value, a different vulnerability than CVE-2011-1184.
CVE-2011-5062
The HTTP Digest Access Authentication implementation in Apache Tomcat ...
ELSA-2011-1845
ELSA-2011-1845: tomcat5 security update (MODERATE)
ELSA-2011-1780
ELSA-2011-1780: tomcat6 security and bug fix update (MODERATE)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-4f7h-9j2x-cmr4 Improper Authentication in Apache Tomcat | 3% Низкий | около 3 лет назад | ||
![]() | CVE-2011-5062 The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qop values, which might allow remote attackers to bypass intended integrity-protection requirements via a qop=auth value, a different vulnerability than CVE-2011-1184. | CVSS2: 5 | 3% Низкий | больше 13 лет назад |
![]() | CVE-2011-5062 The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qop values, which might allow remote attackers to bypass intended integrity-protection requirements via a qop=auth value, a different vulnerability than CVE-2011-1184. | CVSS2: 4.3 | 3% Низкий | больше 13 лет назад |
![]() | CVE-2011-5062 The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qop values, which might allow remote attackers to bypass intended integrity-protection requirements via a qop=auth value, a different vulnerability than CVE-2011-1184. | CVSS2: 5 | 3% Низкий | больше 13 лет назад |
CVE-2011-5062 The HTTP Digest Access Authentication implementation in Apache Tomcat ... | CVSS2: 5 | 3% Низкий | больше 13 лет назад | |
ELSA-2011-1845 ELSA-2011-1845: tomcat5 security update (MODERATE) | больше 13 лет назад | |||
ELSA-2011-1780 ELSA-2011-1780: tomcat6 security and bug fix update (MODERATE) | больше 13 лет назад |
Уязвимостей на страницу