PT-2011-2926 · Apache+4 · Apache Tomcat+4
Publicado
2011-08-18
·
Atualizado
2023-02-13
·
CVE-2011-1184
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Tomcat versions 5.5.x through 5.5.33
Apache Tomcat versions 6.x through 6.0.32
Apache Tomcat versions 7.x through 7.0.11
Description
The issue concerns the HTTP Digest Access Authentication implementation, which lacks proper countermeasures against replay attacks. This allows remote attackers to bypass access restrictions by sniffing the network for valid requests. The problem is related to the lack of checking of
nonce (server nonce) and nc (nonce-count or client nonce count) values.Recommendations
For Apache Tomcat versions 5.5.x through 5.5.33, update to version 5.5.34 or later.
For Apache Tomcat versions 6.x through 6.0.32, update to version 6.0.33 or later.
For Apache Tomcat versions 7.x through 7.0.11, update to version 7.0.12 or later.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache Tomcat
Centos
Hp-Ux
Red Hat
Suse