Apache Tomcat 7.0.x < 7.0.19 Multiple Vulnerabilities

Medium Nessus Network Monitor Plugin ID 5996


The remote web server is affected by multiple vulnerabilities.


Versions of Tomcat 7.0.x earlier than 7.0.19 are potentially affected by multiple vulnerabilities :

- An issue exists in the error handling related to the MemoryUserDatabase that allows user passwords to be disclosed through log files. (CVE-2011-2204)

- An input validation issue exists that allows a local attacker to either bypass security or carry out denial of service attacks when the APR or NIO connectors are enabled. (CVE-2011-2526)


Upgrade to Apache Tomcat 7.0.19 or later.

See Also


Plugin Details

Severity: Medium

ID: 5996

File Name: 5996.prm

Family: Web Servers

Published: 2011/08/01

Modified: 2016/01/19

Dependencies: 3057

Nessus ID: 55759

Risk Information

Risk Factor: Medium


Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:U/RL:OF/RC:C


Base Score: 5.6

Temporal Score: 4.9


Temporal Vector: CVSS3#E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:apache:tomcat

Patch Publication Date: 2011/07/19

Vulnerability Publication Date: 2011/06/27

Reference Information

CVE: CVE-2011-2204, CVE-2011-2481, CVE-2011-2526

BID: 48667, 49147