Lucene search

K
f5F5F5:K36784855
HistoryNov 14, 2016 - 12:00 a.m.

K36784855 : Apache Tomcat vulnerability CVE-2016-0762

2016-11-1400:00:00
my.f5.com
26

AI Score

7.3

Confidence

High

EPSS

0.001

Percentile

49.0%

Security Advisory Description

The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not process the supplied password if the supplied user name did not exist. This made a timing attack possible to determine valid user names. Note that the default configuration includes the LockOutRealm which makes exploitation of this vulnerability harder. (CVE-2016-0762)

Impact

This vulnerability may allow unauthorized disclosure of information.