CVE-2011-1184
published 2012-01-14CVE-2011-1184: The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not have the expected…
PriorityP335medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
8.54%
94.5th percentile
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not have the expected countermeasures against replay attacks, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, related to lack of checking of nonce (aka server nonce) and nc (aka nonce-count or client nonce count) values.
Affected
94 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
ghsa5.0MEDIUM
osv5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Access Control in Apache Tomcat
osv·2022-05-17·CVSS 5.0
CVE-2012-5885 [MEDIUM] Improper Access Control in Apache Tomcat
Improper Access Control in Apache Tomcat
The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 tracks cnonce (aka client nonce) values instead of nonce (aka server nonce) and nc (aka nonce-count) values, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, a different vulnerability than CVE-2011-1184.
GHSA
Improper Access Control in Apache Tomcat
ghsa·2022-05-17·CVSS 5.0
CVE-2012-5885 [MEDIUM] CWE-284 Improper Access Control in Apache Tomcat
Improper Access Control in Apache Tomcat
The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 tracks cnonce (aka client nonce) values instead of nonce (aka server nonce) and nc (aka nonce-count) values, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, a different vulnerability than CVE-2011-1184.
GHSA
Authentication Bypass in Apache Tomcat
ghsa·2022-05-14
CVE-2011-1184 [MEDIUM] Authentication Bypass in Apache Tomcat
Authentication Bypass in Apache Tomcat
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not have the expected countermeasures against replay attacks, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, related to lack of checking of nonce (aka server nonce) and nc (aka nonce-count or client nonce count) values.
GHSA
Improper Authentication in Apache Tomcat
ghsa·2022-05-14·CVSS 5.0
CVE-2011-5062 [MEDIUM] CWE-287 Improper Authentication in Apache Tomcat
Improper Authentication in Apache Tomcat
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qop values, which might allow remote attackers to bypass intended integrity-protection requirements via a qop=auth value, a different vulnerability than CVE-2011-1184.
OSV
Improper Authentication in Apache Tomcat
osv·2022-05-14·CVSS 5.0
CVE-2011-5062 [MEDIUM] Improper Authentication in Apache Tomcat
Improper Authentication in Apache Tomcat
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qop values, which might allow remote attackers to bypass intended integrity-protection requirements via a qop=auth value, a different vulnerability than CVE-2011-1184.
OSV
Authentication Bypass in Apache Tomcat
osv·2022-05-14
CVE-2011-1184 [MEDIUM] Authentication Bypass in Apache Tomcat
Authentication Bypass in Apache Tomcat
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not have the expected countermeasures against replay attacks, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, related to lack of checking of nonce (aka server nonce) and nc (aka nonce-count or client nonce count) values.
OSV
Improper Authentication in Apache Tomcat
osv·2022-05-14·CVSS 5.0
CVE-2011-5063 [MEDIUM] Improper Authentication in Apache Tomcat
Improper Authentication in Apache Tomcat
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check realm values, which might allow remote attackers to bypass intended access restrictions by leveraging the availability of a protection space with weaker authentication or authorization requirements, a different vulnerability than CVE-2011-1184.
OSV
Use of Hard-coded Cryptographic Key in Apache Tomcat
osv·2022-05-14·CVSS 5.0
CVE-2011-5064 [MEDIUM] Use of Hard-coded Cryptographic Key in Apache Tomcat
Use of Hard-coded Cryptographic Key in Apache Tomcat
DigestAuthenticator.java in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 uses Catalina as the hard-coded server secret (aka private key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging knowledge of this string, a different vulnerability than CVE-2011-1184.
GHSA
Improper Authentication in Apache Tomcat
ghsa·2022-05-14·CVSS 5.0
CVE-2011-5063 [MEDIUM] CWE-287 Improper Authentication in Apache Tomcat
Improper Authentication in Apache Tomcat
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check realm values, which might allow remote attackers to bypass intended access restrictions by leveraging the availability of a protection space with weaker authentication or authorization requirements, a different vulnerability than CVE-2011-1184.
GHSA
Use of Hard-coded Cryptographic Key in Apache Tomcat
ghsa·2022-05-14·CVSS 5.0
CVE-2011-5064 [MEDIUM] CWE-321 Use of Hard-coded Cryptographic Key in Apache Tomcat
Use of Hard-coded Cryptographic Key in Apache Tomcat
DigestAuthenticator.java in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 uses Catalina as the hard-coded server secret (aka private key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging knowledge of this string, a different vulnerability than CVE-2011-1184.
Red Hat
tomcat: three DIGEST authentication implementation issues
vendor_redhat·2012-11-05·CVSS 5.0
CVE-2012-5885 [MEDIUM] tomcat: three DIGEST authentication implementation issues
tomcat: three DIGEST authentication implementation issues
The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 tracks cnonce (aka client nonce) values instead of nonce (aka server nonce) and nc (aka nonce-count) values, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, a different vulnerability than CVE-2011-1184.
Package: jbossweb (Red Hat JBoss BRMS 5) - Affected
Package: jbossweb (Red Hat JBoss Data Grid 6) - Affected
Package: tomcat7 (Red Hat JBoss Enterprise Web Server 2) - Not affected
Package: jbossweb (Red Hat JBoss Operations Network 3.1) - Not affected
Package: jbossweb (Red Hat
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2011-11-08·CVSS 5.0
CVE-2011-3190 [MEDIUM] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Tomcat could be made to crash or expose sensitive information over the
network.
It was discovered that Tomcat incorrectly implemented HTTP DIGEST
authentication. An attacker could use this flaw to perform a variety of
authentication attacks. (CVE-2011-1184)
Polina Genova discovered that Tomcat incorrectly created log entries with
passwords when encountering errors during JMX user creation. A local
attacker could possibly use this flaw to obtain sensitive information. This
issue only affected Ubuntu 10.04 LTS, 10.10 and 11.04. (CVE-2011-2204)
It was discovered that Tomcat incorrectly validated certain request
attributes when sendfile is enabled. A local attacker could bypass intended
restrictions, or cause the JVM to crash, resulting in a denial of
Red Hat
tomcat: Multiple weaknesses in HTTP DIGEST authentication
vendor_redhat·2011-09-26·CVSS 5.0
CVE-2011-1184 [MEDIUM] tomcat: Multiple weaknesses in HTTP DIGEST authentication
tomcat: Multiple weaknesses in HTTP DIGEST authentication
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not have the expected countermeasures against replay attacks, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, related to lack of checking of nonce (aka server nonce) and nc (aka nonce-count or client nonce count) values.
Red Hat
tomcat: Multiple weaknesses in HTTP DIGEST authentication
vendor_redhat·2011-09-26·CVSS 5.0
CVE-2011-5064 [MEDIUM] tomcat: Multiple weaknesses in HTTP DIGEST authentication
tomcat: Multiple weaknesses in HTTP DIGEST authentication
DigestAuthenticator.java in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 uses Catalina as the hard-coded server secret (aka private key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging knowledge of this string, a different vulnerability than CVE-2011-1184.
Red Hat
tomcat: Multiple weaknesses in HTTP DIGEST authentication
vendor_redhat·2011-09-26·CVSS 5.0
CVE-2011-5063 [MEDIUM] tomcat: Multiple weaknesses in HTTP DIGEST authentication
tomcat: Multiple weaknesses in HTTP DIGEST authentication
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check realm values, which might allow remote attackers to bypass intended access restrictions by leveraging the availability of a protection space with weaker authentication or authorization requirements, a different vulnerability than CVE-2011-1184.
Red Hat
tomcat: Multiple weaknesses in HTTP DIGEST authentication
vendor_redhat·2011-09-26·CVSS 5.0
CVE-2011-5062 [MEDIUM] tomcat: Multiple weaknesses in HTTP DIGEST authentication
tomcat: Multiple weaknesses in HTTP DIGEST authentication
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qop values, which might allow remote attackers to bypass intended integrity-protection requirements via a qop=auth value, a different vulnerability than CVE-2011-1184.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-1184 CVE-2011-5062 CVE-2011-5063 CVE-2011-5064 tomcat: Multiple weaknesses in HTTP DIGEST authentication
bugzilla·2011-09-26·CVSS 5.0
CVE-2011-1184 [MEDIUM] CVE-2011-1184 CVE-2011-5062 CVE-2011-5063 CVE-2011-5064 tomcat: Multiple weaknesses in HTTP DIGEST authentication
CVE-2011-1184 CVE-2011-5062 CVE-2011-5063 CVE-2011-5064 tomcat: Multiple weaknesses in HTTP DIGEST authentication
Multiple security flaws were found in the Apache Tomcat HTTP DIGEST (RFC 2069) Authentication implementation:
* it was possible to perform session reply attacks,
* server generated nonce-values were not checked,
* count of client generated nonce-values were not checked,
* quality of protection (qop) values were not checked,
* realms values were not checked,
* a known, hard-coded string was used as server secret.
References:
[1] http://tomcat.apache.org/security-5.html
[2] http://tomcat.apache.org/security-6.html
[3] http://www.securityfocus.com/archive/1/519818/30/0/threaded
Relevant upstream patches:
[4] http://svn.apache.org/viewvc?view=revision&revision=1158180
(for Tomca
Bugzilla
CVE-2011-1184 tomcat5: Multiple weaknesses in the HTTP DIGEST authentication [fedora-16]
bugzilla·2011-09-26·CVSS 5.0
CVE-2011-1184 [MEDIUM] CVE-2011-1184 tomcat5: Multiple weaknesses in the HTTP DIGEST authentication [fedora-16]
CVE-2011-1184 tomcat5: Multiple weaknesses in the HTTP DIGEST authentication [fedora-16]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=741401
Please note: this issue af
Bugzilla
CVE-2011-1184 tomcat5, tomcat6: Multiple weaknesses in the HTTP DIGEST authentication [fedora-all]
bugzilla·2011-09-26·CVSS 5.0
CVE-2011-1184 [MEDIUM] CVE-2011-1184 tomcat5, tomcat6: Multiple weaknesses in the HTTP DIGEST authentication [fedora-all]
CVE-2011-1184 tomcat5, tomcat6: Multiple weaknesses in the HTTP DIGEST authentication [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=741401
Please note: thi
http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-02/msg00006.htmlhttp://marc.info/?l=bugtraq&m=133469267822771&w=2http://marc.info/?l=bugtraq&m=136485229118404&w=2http://marc.info/?l=bugtraq&m=139344343412337&w=2http://rhn.redhat.com/errata/RHSA-2012-0074.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0075.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0076.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0077.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0078.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0325.htmlhttp://secunia.com/advisories/57126http://svn.apache.org/viewvc?view=rev&rev=1087655http://svn.apache.org/viewvc?view=rev&rev=1158180http://svn.apache.org/viewvc?view=rev&rev=1159309http://tomcat.apache.org/security-5.htmlhttp://tomcat.apache.org/security-6.htmlhttp://tomcat.apache.org/security-7.htmlhttp://www.debian.org/security/2012/dsa-2401http://www.mandriva.com/security/advisories?name=MDVSA-2011:156http://www.redhat.com/support/errata/RHSA-2011-1845.htmlhttps://lists.apache.org/thread.html/06cfb634bc7bf37af7d8f760f118018746ad8efbd519c4b789ac9c2e%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/8dcaf7c3894d66cb717646ea1504ea6e300021c85bb4e677dc16b1aa%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r3aacc40356defc3f248aa504b1e48e819dd0471a0a83349080c6bcbf%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r584a714f141eff7b1c358d4679288177bd4ca4558e9999d15867d4b5%40%3Cdev.tomcat.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19169http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-02/msg00006.htmlhttp://marc.info/?l=bugtraq&m=133469267822771&w=2http://marc.info/?l=bugtraq&m=136485229118404&w=2http://marc.info/?l=bugtraq&m=139344343412337&w=2http://rhn.redhat.com/errata/RHSA-2012-0074.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0075.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0076.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0077.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0078.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0325.htmlhttp://secunia.com/advisories/57126http://svn.apache.org/viewvc?view=rev&rev=1087655http://svn.apache.org/viewvc?view=rev&rev=1158180http://svn.apache.org/viewvc?view=rev&rev=1159309http://tomcat.apache.org/security-5.htmlhttp://tomcat.apache.org/security-6.htmlhttp://tomcat.apache.org/security-7.htmlhttp://www.debian.org/security/2012/dsa-2401http://www.mandriva.com/security/advisories?name=MDVSA-2011:156http://www.redhat.com/support/errata/RHSA-2011-1845.htmlhttps://lists.apache.org/thread.html/06cfb634bc7bf37af7d8f760f118018746ad8efbd519c4b789ac9c2e%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/8dcaf7c3894d66cb717646ea1504ea6e300021c85bb4e677dc16b1aa%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r3aacc40356defc3f248aa504b1e48e819dd0471a0a83349080c6bcbf%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r584a714f141eff7b1c358d4679288177bd4ca4558e9999d15867d4b5%40%3Cdev.tomcat.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19169
2012-01-14
Published