CVE-2011-5063
published 2012-01-14CVE-2011-5063: The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check realm…
PriorityP432medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
6.63%
93.2th percentile
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check realm values, which might allow remote attackers to bypass intended access restrictions by leveraging the availability of a protection space with weaker authentication or authorization requirements, a different vulnerability than CVE-2011-1184.
Affected
76 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
ghsa5.0MEDIUM
osv5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
tomcat: Multiple weaknesses in HTTP DIGEST authentication
vendor_redhat·2011-09-26·CVSS 5.0
CVE-2011-5063 [MEDIUM] tomcat: Multiple weaknesses in HTTP DIGEST authentication
tomcat: Multiple weaknesses in HTTP DIGEST authentication
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check realm values, which might allow remote attackers to bypass intended access restrictions by leveraging the availability of a protection space with weaker authentication or authorization requirements, a different vulnerability than CVE-2011-1184.
OSV
Improper Authentication in Apache Tomcat
osv·2022-05-14·CVSS 5.0
CVE-2011-5063 [MEDIUM] Improper Authentication in Apache Tomcat
Improper Authentication in Apache Tomcat
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check realm values, which might allow remote attackers to bypass intended access restrictions by leveraging the availability of a protection space with weaker authentication or authorization requirements, a different vulnerability than CVE-2011-1184.
GHSA
Improper Authentication in Apache Tomcat
ghsa·2022-05-14·CVSS 5.0
CVE-2011-5063 [MEDIUM] CWE-287 Improper Authentication in Apache Tomcat
Improper Authentication in Apache Tomcat
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check realm values, which might allow remote attackers to bypass intended access restrictions by leveraging the availability of a protection space with weaker authentication or authorization requirements, a different vulnerability than CVE-2011-1184.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-5063 tomcat: Bypass intended integrity protection due to incorrect realm checking
bugzilla·2012-01-16·CVSS 4.3
CVE-2011-5063 [MEDIUM] CVE-2011-5063 tomcat: Bypass intended integrity protection due to incorrect realm checking
CVE-2011-5063 tomcat: Bypass intended integrity protection due to incorrect realm checking
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check realm values, which might allow remote attackers to bypass intended access restrictions by leveraging the availability of a protection space with weaker authentication or authorization requirements.
References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-5063
Discussion:
*** This bug has been marked as a duplicate of bug 741401 ***
Bugzilla
CVE-2011-1184 CVE-2011-5062 CVE-2011-5063 CVE-2011-5064 tomcat: Multiple weaknesses in HTTP DIGEST authentication
bugzilla·2011-09-26·CVSS 5.0
CVE-2011-1184 [MEDIUM] CVE-2011-1184 CVE-2011-5062 CVE-2011-5063 CVE-2011-5064 tomcat: Multiple weaknesses in HTTP DIGEST authentication
CVE-2011-1184 CVE-2011-5062 CVE-2011-5063 CVE-2011-5064 tomcat: Multiple weaknesses in HTTP DIGEST authentication
Multiple security flaws were found in the Apache Tomcat HTTP DIGEST (RFC 2069) Authentication implementation:
* it was possible to perform session reply attacks,
* server generated nonce-values were not checked,
* count of client generated nonce-values were not checked,
* quality of protection (qop) values were not checked,
* realms values were not checked,
* a known, hard-coded string was used as server secret.
References:
[1] http://tomcat.apache.org/security-5.html
[2] http://tomcat.apache.org/security-6.html
[3] http://www.securityfocus.com/archive/1/519818/30/0/threaded
Relevant upstream patches:
[4] http://svn.apache.org/viewvc?view=revision&revision=1158180
(for Tomca
Bugzilla
libpng10, libpng: Memory leak by write of iCCP chunk with negative embedded profile length (CVE-2006-7244, CVE-2009-5063)
bugzilla·2011-03-23·CVSS 5.0
CVE-2006-7244 [MEDIUM] libpng10, libpng: Memory leak by write of iCCP chunk with negative embedded profile length (CVE-2006-7244, CVE-2009-5063)
libpng10, libpng: Memory leak by write of iCCP chunk with negative embedded profile length (CVE-2006-7244, CVE-2009-5063)
A memory leak was found in the way libpng, PNG image format files
manipulating library, processed image files with negative length
of embedded International Color Consortium (ICC) profile chunk.
A remote attacker could provide a specially-crafted JPEG image
format file and trick the local user into opening it with an
application linked against libpng, which would result in
denial of service (excessive memory consumption or that particular
application crash).
References:
[1] http://www.openwall.com/lists/oss-security/2011/03/22/7 (CVE Request)
Discussion:
As noted in [1]:
i), the bug was introduced in 1.2.13beta1:
http://libpng.git.sourceforge.net/git/gitweb.cgi?p=l
http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-02/msg00006.htmlhttp://marc.info/?l=bugtraq&m=139344343412337&w=2http://rhn.redhat.com/errata/RHSA-2012-0074.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0075.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0076.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0077.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0078.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0325.htmlhttp://secunia.com/advisories/57126http://svn.apache.org/viewvc?view=rev&rev=1087655http://svn.apache.org/viewvc?view=rev&rev=1158180http://svn.apache.org/viewvc?view=rev&rev=1159309http://tomcat.apache.org/security-5.htmlhttp://tomcat.apache.org/security-6.htmlhttp://tomcat.apache.org/security-7.htmlhttp://www.debian.org/security/2012/dsa-2401http://www.redhat.com/support/errata/RHSA-2011-1845.htmlhttps://lists.apache.org/thread.html/06cfb634bc7bf37af7d8f760f118018746ad8efbd519c4b789ac9c2e%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/8dcaf7c3894d66cb717646ea1504ea6e300021c85bb4e677dc16b1aa%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r3aacc40356defc3f248aa504b1e48e819dd0471a0a83349080c6bcbf%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r584a714f141eff7b1c358d4679288177bd4ca4558e9999d15867d4b5%40%3Cdev.tomcat.apache.org%3Ehttp://lists.opensuse.org/opensuse-security-announce/2012-02/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-02/msg00006.htmlhttp://marc.info/?l=bugtraq&m=139344343412337&w=2http://rhn.redhat.com/errata/RHSA-2012-0074.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0075.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0076.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0077.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0078.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0325.htmlhttp://secunia.com/advisories/57126http://svn.apache.org/viewvc?view=rev&rev=1087655http://svn.apache.org/viewvc?view=rev&rev=1158180http://svn.apache.org/viewvc?view=rev&rev=1159309http://tomcat.apache.org/security-5.htmlhttp://tomcat.apache.org/security-6.htmlhttp://tomcat.apache.org/security-7.htmlhttp://www.debian.org/security/2012/dsa-2401http://www.redhat.com/support/errata/RHSA-2011-1845.htmlhttps://lists.apache.org/thread.html/06cfb634bc7bf37af7d8f760f118018746ad8efbd519c4b789ac9c2e%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/8dcaf7c3894d66cb717646ea1504ea6e300021c85bb4e677dc16b1aa%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r3aacc40356defc3f248aa504b1e48e819dd0471a0a83349080c6bcbf%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r584a714f141eff7b1c358d4679288177bd4ca4558e9999d15867d4b5%40%3Cdev.tomcat.apache.org%3E
2012-01-14
Published