Apache Tomcat 7.0.x < 7.0.19 Multiple Vulnerabilities

medium Log Correlation Engine Plugin ID 800597

Synopsis

The remote web server is affected by multiple vulnerabilities.

Description

Versions of Tomcat 7.0.x earlier than 7.0.19 are potentially affected by multiple vulnerabilities :

- An issue exists in the error handling related to the MemoryUserDatabase that allows user passwords to be disclosed through log files. (CVE-2011-2204)

- An input validation issue exists that allows a local attacker to either bypass security or carry out denial of service attacks when the APR or NIO connectors are enabled. (CVE-2011-2526)

Solution

Upgrade to Apache Tomcat 7.0.19 or later.

See Also

tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.19

Plugin Details

Severity: Medium

ID: 800597

Family: Web Servers

Published: 8/1/2011

Updated: 8/1/2011

Nessus ID: 55759

Risk Information

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

Vulnerability Information

Patch Publication Date: 7/19/2011

Vulnerability Publication Date: 6/27/2011

Reference Information

CVE: CVE-2011-2204, CVE-2011-2526, CVE-2011-2481

BID: 48667, 49147