Apache Tomcat SingleSignOn Remote Information Disclosure Vulnerability
BID:27365
Info
Apache Tomcat SingleSignOn Remote Information Disclosure Vulnerability
| Bugtraq ID: | 27365 |
| Class: | Design Error |
| CVE: |
CVE-2008-0128 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 20 2008 12:00AM |
| Updated: | Mar 19 2015 09:29AM |
| Credit: | Olaf Kock discovered this issue. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 9 SP3 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE SUSE Linux Enterprise SDK 10 SP1 SuSE SUSE Linux Enterprise SDK 10 SuSE SUSE Linux Enterprise Desktop 10 SP1 SuSE SUSE Linux Enterprise Desktop 10 SuSE SUSE Linux Enterprise 10 SP1 DEBUGINFO SuSE openSUSE 10.3 SuSE Linux Professional 10.2 x86_64 SuSE Linux Personal 10.2 x86_64 S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. SuSE Linux Open-Xchange 4.1 S.u.S.E. openSUSE 10.2 S.u.S.E. openSUSE 10.1 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Open-Enterprise-Server 1 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Office Server S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop SDK 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Novell Linux Desktop 1.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 10.2 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 10.2 S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux Desktop 10 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc S.u.S.E. Linux 10.0 x86-64 S.u.S.E. Linux 10.0 x86 S.u.S.E. Linux 10.0 ppc RedHat Red Hat Network Satellite (for RHEL 4) 5.1 RedHat Certificate Server 7.3 Red Hat Red Hat Network Satellite Server 5.0 Red Hat Red Hat Network Satellite Server 4.2 Novell ZENworks Linux Management 7.3 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Computer Associates Cohesion Application Configuration Manager 4.5 Apache Software Foundation Tomcat 5.5.20 |
| Not Vulnerable: |
Computer Associates Cohesion Application Configuration Manager 4.5 SP1 Apache Software Foundation Tomcat 5.5.21 |
Discussion
Apache Tomcat SingleSignOn Remote Information Disclosure Vulnerability
Apache Tomcat is prone to a remote information-disclosure vulnerability because the application fails to properly restrict access to sensitive information.
Remote attackers can exploit this issue to obtain confidential user-authentication credentials.
The issue affects Tomcat 5.5.20; prior versions may also be vulnerable.
Apache Tomcat is prone to a remote information-disclosure vulnerability because the application fails to properly restrict access to sensitive information.
Remote attackers can exploit this issue to obtain confidential user-authentication credentials.
The issue affects Tomcat 5.5.20; prior versions may also be vulnerable.
Exploit / POC
Apache Tomcat SingleSignOn Remote Information Disclosure Vulnerability
Attackers can exploit this issue using readily available tools.
Attackers can exploit this issue using readily available tools.
Solution / Fix
Apache Tomcat SingleSignOn Remote Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Apache Tomcat SingleSignOn Remote Information Disclosure Vulnerability
References:
References:
- Apache Tomcat Homepage (Apache)
- ASF Bugzilla Bug 41217 SingleSignOn Cookie does not honor https access: Login In (Apache)
- Debian Tracker CVE-2008-0128 (Debian)
- ZLM 7.3 IR3 Tomcat 5.0.30 to fix reported security vulnerabilities (Novell)
- CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities (Updated - v1.1) ("Williams, James K"
) - CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities (Computer Associates)
- CA20090123-01: Security Notice for Cohesion Tomcat (Computer Associates)
- RHSA-2008-0524-4 Red Hat Network Satellite Server security update (Red Hat)
- RHSA-2008:0261-4 Moderate: Red Hat Network Satellite Server security update (Red Hat)
- RHSA-2008:0630-3 Low: Red Hat Network Satellite Server security update (Red Hat)
- Tomcat 5.0.28 in ZLM 7.3 subject to "Multiple Vendor Multiple HTTP Request Smugg (Novell)
- Tomcat 5.0.28 in ZLM 7.3 subject to Multiple Vendor Multiple HTTP Request Smuggl (Novell)