Lucene search

K
githubGitHub Advisory DatabaseGHSA-HJFH-7C4V-7Q8H
HistoryMay 02, 2022 - 3:39 a.m.

Improper Authentication in Apache Tomcat

2022-05-0203:39:47
CWE-287
GitHub Advisory Database
github.com
17
apache tomcat
authentication
autodeploy
remote attackers
http requests

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS

0.002

Percentile

57.7%

The autodeployment process in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20, when autoDeploy is enabled, deploys appBase files that remain from a failed undeploy, which might allow remote attackers to bypass intended authentication requirements via HTTP requests.

Affected configurations

Vulners
Node
org.apache.tomcattomcatRange6.0.06.0.24
OR
org.apache.tomcattomcatRange5.5.05.5.28
VendorProductVersionCPE
org.apache.tomcattomcat*cpe:2.3:a:org.apache.tomcat:tomcat:*:*:*:*:*:*:*:*

References

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS

0.002

Percentile

57.7%