Apache Tomcat SSL Anonymous Cipher Configuration Information Disclosure Vulnerability
BID:28482
Info
Apache Tomcat SSL Anonymous Cipher Configuration Information Disclosure Vulnerability
| Bugtraq ID: | 28482 |
| Class: | Configuration Error |
| CVE: |
CVE-2007-1858 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 04 2007 12:00AM |
| Updated: | Mar 19 2015 08:51AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server SDK 9 SuSE SUSE Linux Enterprise Server 9 SP3 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise SDK 10 SP1 SuSE SUSE Linux Enterprise SDK 10 SuSE SUSE Linux Enterprise Desktop 10 SP1 SuSE SUSE Linux Enterprise Desktop 10 SuSE openSUSE 10.3 SuSE Linux Professional 10.2 x86_64 SuSE Linux Personal 10.2 x86_64 S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. SuSE Linux Open-Xchange 4.1 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Office Server S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop SDK 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 10.2 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 10.2 S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux Enterprise Server for S/390 9.0 S.u.S.E. Linux Enterprise Server for S/390 S.u.S.E. Linux Desktop 1.0 S.u.S.E. Linux Desktop 10 S.u.S.E. Linux Database Server 0 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc S.u.S.E. Linux 10.0 x86-64 S.u.S.E. Linux 10.0 x86 S.u.S.E. Linux 10.0 ppc Research In Motion Blackberry Enterprise Server for Novell Groupwise 5.0.1 Research In Motion Blackberry Enterprise Server for Novell Groupwise 4.1.7 Research In Motion Blackberry Enterprise Server for Novell Groupwise 4.1.4 Research In Motion Blackberry Enterprise Server for Exchange 5.0.2 MR1 Research In Motion Blackberry Enterprise Server for Exchange 5.0.2 Research In Motion Blackberry Enterprise Server for Exchange 5.0.1 Research In Motion Blackberry Enterprise Server for Exchange 5.0 SP2 Research In Motion Blackberry Enterprise Server for Exchange 5.0 Research In Motion Blackberry Enterprise Server for Exchange 4.1.7 Research In Motion Blackberry Enterprise Server for Exchange 4.1.4 Research In Motion Blackberry Enterprise Server for Domino 5.0.2 MR1 Research In Motion Blackberry Enterprise Server for Domino 4.1.4 Research In Motion Blackberry Enterprise Server Express for Exchange 5.0.2 MR1 Research In Motion Blackberry Enterprise Server Express for Exchange 5.0.2 Research In Motion Blackberry Enterprise Server Express for Exchange 5.0.1 Research In Motion Blackberry Enterprise Server Express for Exchange 4.1.4 Research In Motion Blackberry Enterprise Server Express for Domino 5.0.2 MR1 Research In Motion Blackberry Enterprise Server Express for Domino 5.0.2 Research In Motion Blackberry Enterprise Server Express for Domino 4.1.4 Novell ZENworks Linux Management 7.3 HP Network Node Manager i 9.10 HP Network Node Manager i 9.03 HP Network Node Manager i 9.02 HP Network Node Manager i 9.01 HP Network Node Manager i 9.00 HP Network Node Manager i 9.0 HP Network Node Manager i 8.1 HP HP-UX B.11.31 HP HP-UX B.11.23 Computer Associates Cohesion Application Configuration Manager 4.5 Apache Software Foundation Tomcat 5.5.17 Apache Software Foundation Tomcat 5.5.16 Apache Software Foundation Tomcat 5.5.15 Apache Software Foundation Tomcat 5.5.14 Apache Software Foundation Tomcat 5.5.13 Apache Software Foundation Tomcat 5.5.12 Apache Software Foundation Tomcat 5.5.11 Apache Software Foundation Tomcat 5.5.10 Apache Software Foundation Tomcat 5.5.1 Apache Software Foundation Tomcat 5.5 Apache Software Foundation Tomcat 5.0.30 Apache Software Foundation Tomcat 5.0.28 Apache Software Foundation Tomcat 5.0.19 Apache Software Foundation Tomcat 5.0.16 Apache Software Foundation Tomcat 5.0.15 Apache Software Foundation Tomcat 5.0.14 Apache Software Foundation Tomcat 5.0.13 Apache Software Foundation Tomcat 5.0.12 Apache Software Foundation Tomcat 5.0.11 Apache Software Foundation Tomcat 5.0.10 Apache Software Foundation Tomcat 5.0.3 Apache Software Foundation Tomcat 5.0.2 Apache Software Foundation Tomcat 5.0.1 Apache Software Foundation Tomcat 5.0 Apache Software Foundation Tomcat 4.1.31 Apache Software Foundation Tomcat 4.1.30 Apache Software Foundation Tomcat 4.1.29 Apache Software Foundation Tomcat 4.1.28 |
| Not Vulnerable: |
Computer Associates Cohesion Application Configuration Manager 4.5 SP1 Apache Software Foundation Tomcat 5.5.18 Apache Software Foundation Tomcat 5.0.31 Apache Software Foundation Tomcat 4.1.32 |
Discussion
Apache Tomcat SSL Anonymous Cipher Configuration Information Disclosure Vulnerability
Apache Tomcat is prone to a remote information-disclosure vulnerability.
An attacker can exploit this issue to obtain sensitive information that may lead to further attacks.
Apache Tomcat is prone to a remote information-disclosure vulnerability.
An attacker can exploit this issue to obtain sensitive information that may lead to further attacks.
Exploit / POC
Apache Tomcat SSL Anonymous Cipher Configuration Information Disclosure Vulnerability
An attacker can use readily available network utilities to exploit this issue.
An attacker can use readily available network utilities to exploit this issue.
Solution / Fix
Apache Tomcat SSL Anonymous Cipher Configuration Information Disclosure Vulnerability
Solution:
The vendor has released fixes. Please see the references for more information.
Apache Tomcat 4.1.28
Apache Tomcat 4.1.29
Apache Tomcat 4.1.30
Apache Tomcat 4.1.31
Apache Tomcat 5.0.1
Apache Tomcat 5.0.10
Apache Tomcat 5.0.11
Apache Tomcat 5.0.12
Apache Tomcat 5.0.13
Apache Tomcat 5.0.15
Apache Tomcat 5.0.19
Apache Tomcat 5.0.3
Apache Tomcat 5.5.10
Apache Tomcat 5.5.11
Apache Tomcat 5.5.13
Apache Tomcat 5.5.16
Solution:
The vendor has released fixes. Please see the references for more information.
Apache Tomcat 4.1.28
-
Apache Software Foundation apache-tomcat-4.1.32.zip
http://archive.apache.org/dist/tomcat/tomcat-4/v4.1.32/bin/apache-tomc at-4.1.32.zip -
Apache Software Foundation apache-tomcat-5.5.20.zip
http://archive.apache.org/dist/tomcat/tomcat-5/v5.5.20/bin/apache-tomc at-5.5.20.zip
Apache Tomcat 4.1.29
-
Apache Software Foundation apache-tomcat-4.1.32.zip
http://archive.apache.org/dist/tomcat/tomcat-4/v4.1.32/bin/apache-tomc at-4.1.32.zip -
Apache Software Foundation apache-tomcat-5.5.20.zip
http://archive.apache.org/dist/tomcat/tomcat-5/v5.5.20/bin/apache-tomc at-5.5.20.zip
Apache Tomcat 4.1.30
-
Apache Software Foundation apache-tomcat-4.1.32.zip
http://archive.apache.org/dist/tomcat/tomcat-4/v4.1.32/bin/apache-tomc at-4.1.32.zip -
Apache Software Foundation apache-tomcat-5.5.20.zip
http://archive.apache.org/dist/tomcat/tomcat-5/v5.5.20/bin/apache-tomc at-5.5.20.zip
Apache Tomcat 4.1.31
-
Apache Software Foundation apache-tomcat-4.1.32.zip
http://archive.apache.org/dist/tomcat/tomcat-4/v4.1.32/bin/apache-tomc at-4.1.32.zip -
Apache Software Foundation apache-tomcat-5.5.20.zip
http://archive.apache.org/dist/tomcat/tomcat-5/v5.5.20/bin/apache-tomc at-5.5.20.zip
Apache Tomcat 5.0.1
-
Apache Software Foundation jakarta-tomcat-5.0.30.zip
http://archive.apache.org/dist/tomcat/tomcat-5/v5.0.30/bin/jakarta-tom cat-5.0.30.zip
Apache Tomcat 5.0.10
-
Apache Software Foundation jakarta-tomcat-5.0.30.zip
http://archive.apache.org/dist/tomcat/tomcat-5/v5.0.30/bin/jakarta-tom cat-5.0.30.zip
Apache Tomcat 5.0.11
-
Apache Software Foundation jakarta-tomcat-5.0.30.zip
http://archive.apache.org/dist/tomcat/tomcat-5/v5.0.30/bin/jakarta-tom cat-5.0.30.zip
Apache Tomcat 5.0.12
-
Apache Software Foundation jakarta-tomcat-5.0.30.zip
http://archive.apache.org/dist/tomcat/tomcat-5/v5.0.30/bin/jakarta-tom cat-5.0.30.zip
Apache Tomcat 5.0.13
-
Apache Software Foundation jakarta-tomcat-5.0.30.zip
http://archive.apache.org/dist/tomcat/tomcat-5/v5.0.30/bin/jakarta-tom cat-5.0.30.zip
Apache Tomcat 5.0.15
-
Apache Software Foundation jakarta-tomcat-5.0.30.zip
http://archive.apache.org/dist/tomcat/tomcat-5/v5.0.30/bin/jakarta-tom cat-5.0.30.zip
Apache Tomcat 5.0.19
-
Apache Software Foundation jakarta-tomcat-5.0.30.zip
http://archive.apache.org/dist/tomcat/tomcat-5/v5.0.30/bin/jakarta-tom cat-5.0.30.zip
Apache Tomcat 5.0.3
-
Apache Software Foundation jakarta-tomcat-5.0.30.zip
http://archive.apache.org/dist/tomcat/tomcat-5/v5.0.30/bin/jakarta-tom cat-5.0.30.zip
Apache Tomcat 5.5.10
-
Apache Software Foundation apache-tomcat-5.5.20.zip
http://archive.apache.org/dist/tomcat/tomcat-5/v5.5.20/bin/apache-tomc at-5.5.20.zip
Apache Tomcat 5.5.11
-
Apache Software Foundation apache-tomcat-5.5.20.zip
http://archive.apache.org/dist/tomcat/tomcat-5/v5.5.20/bin/apache-tomc at-5.5.20.zip
Apache Tomcat 5.5.13
-
Apache Software Foundation apache-tomcat-5.5.20.zip
http://archive.apache.org/dist/tomcat/tomcat-5/v5.5.20/bin/apache-tomc at-5.5.20.zip
Apache Tomcat 5.5.16
-
Apache Software Foundation apache-tomcat-5.5.20.zip
http://archive.apache.org/dist/tomcat/tomcat-5/v5.5.20/bin/apache-tomc at-5.5.20.zip
References
Apache Tomcat SSL Anonymous Cipher Configuration Information Disclosure Vulnerability
References:
References:
- Apache Tomcat 4.x vulnerabilities (Apache)
- Apache Tomcat 5.x vulnerabilities (Apache)
- Apache Tomcat Homepage (Apache)
- ZLM 7.3 IR3 Tomcat 5.0.30 to fix reported security vulnerabilities (Novell)
- [security bulletin] HPSBMU02744 SSRT100776 rev.1 - HP Network Node Manager i (NN ([email protected])
- CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities (Updated - v1.1) ("Williams, James K"
) - CA20090123-01: Security Notice for Cohesion Tomcat (Computer Associates)
- HPSBMU02744 SSRT100776 rev.2 - HP Network Node Manager i (NNMi) for HP-UX, Linux (HP)
- Tomcat 5.0.28 in ZLM 7.3 subject to "Multiple Vendor Multiple HTTP Request Smugg (Novell)
- Tomcat 5.0.28 in ZLM 7.3 subject to Multiple Vendor Multiple HTTP Request Smuggl (Novell)
- Vulnerabilities in Apache Tomcat implementation impact BlackBerry Enterprise Ser (Research In Motion)