Apache Tomcat Login Constraints Security Bypass Vulnerability
BID:47196
Info
Apache Tomcat Login Constraints Security Bypass Vulnerability
| Bugtraq ID: | 47196 |
| Class: | Design Error |
| CVE: |
CVE-2011-1183 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 06 2011 12:00AM |
| Updated: | Jun 25 2012 12:30PM |
| Credit: | Apache Tomcat security team |
| Vulnerable: |
Gentoo Linux Apache Software Foundation Tomcat 7.0.11 |
| Not Vulnerable: |
Apache Software Foundation Tomcat 7.0.12 |
Discussion
Apache Tomcat Login Constraints Security Bypass Vulnerability
Apache Tomcat is prone to a security-bypass vulnerability.
Successful exploits will allow attackers to bypass certain authentication and obtain sensitive information.
This issue was introduced in Apache Tomcat 7.0.11.
Apache Tomcat is prone to a security-bypass vulnerability.
Successful exploits will allow attackers to bypass certain authentication and obtain sensitive information.
This issue was introduced in Apache Tomcat 7.0.11.
Exploit / POC
Apache Tomcat Login Constraints Security Bypass Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apache Tomcat Login Constraints Security Bypass Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Apache Software Foundation Tomcat 7.0.11
Solution:
Vendor updates are available. Please see the references for more information.
Apache Software Foundation Tomcat 7.0.11
-
Apache Software Foundation apache-tomcat-7.0.12.zip
http://apache.mirror.iweb.ca/tomcat/tomcat-7/v7.0.12/binhttp://apache. mirror.iweb.ca/tomcat/tomcat-7/v7.0.12/bin/apache-tomcat-7.0.12.zip
References
Apache Tomcat Login Constraints Security Bypass Vulnerability
References:
References:
- [SECURITY] CVE-2011-1183 Apache Tomcat security constraint bypass (Apache Software Foundation)
- Apache Tomcat Homepage (Apache)