Lucene search

K
cvelistMitreCVELIST:CVE-2011-5064
HistoryJan 14, 2012 - 9:00 p.m.

CVE-2011-5064

2012-01-1421:00:00
mitre
www.cve.org

4.8 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

67.9%

DigestAuthenticator.java in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 uses Catalina as the hard-coded server secret (aka private key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging knowledge of this string, a different vulnerability than CVE-2011-1184.

References