Lucene search

K
githubGitHub Advisory DatabaseGHSA-4F7H-9J2X-CMR4
HistoryMay 14, 2022 - 1:17 a.m.

Improper Authentication in Apache Tomcat

2022-05-1401:17:03
CWE-287
GitHub Advisory Database
github.com
17
apache tomcat
remote attackers
integrity-protection

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.002

Percentile

55.4%

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qop values, which might allow remote attackers to bypass intended integrity-protection requirements via a qop=auth value, a different vulnerability than CVE-2011-1184.

Affected configurations

Vulners
Node
org.apache.tomcattomcatRange7.0.07.0.12
OR
org.apache.tomcattomcatRange6.0.06.0.33
OR
org.apache.tomcattomcatRange5.5.05.5.34
VendorProductVersionCPE
org.apache.tomcattomcat*cpe:2.3:a:org.apache.tomcat:tomcat:*:*:*:*:*:*:*:*

References

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.002

Percentile

55.4%