Lucene search

K
nessusTenable800783.PRM
HistoryMay 20, 2013 - 12:00 a.m.

Apache Tomcat 6.0.x < 6.0.37 Multiple Vulnerabilities

2013-05-2000:00:00
Tenable
www.tenable.com
14

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.718

Percentile

98.1%

Versions earlier than Apache Tomcat 6.0.37 are potentially affected by multiple vulnerabilities :

  • An error exists related to chunked transfer encoding and extensions that could allow limited denial of service attacks. (CVE-2012-3544)

  • An error exists related to HTML form authentication and session fixation that could allow an attacker to carry out requests using a victim’s credentials. (CVE-2013-2067)

Binary data 800783.prm

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.718

Percentile

98.1%