CVE-2011-5064
published 2012-01-14CVE-2011-5064: DigestAuthenticator.java in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12…
PriorityP431medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
6.57%
93.1th percentile
DigestAuthenticator.java in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 uses Catalina as the hard-coded server secret (aka private key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging knowledge of this string, a different vulnerability than CVE-2011-1184.
Affected
76 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
ghsa5.0MEDIUM
osv5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
tomcat: Multiple weaknesses in HTTP DIGEST authentication
vendor_redhat·2011-09-26·CVSS 5.0
CVE-2011-5064 [MEDIUM] tomcat: Multiple weaknesses in HTTP DIGEST authentication
tomcat: Multiple weaknesses in HTTP DIGEST authentication
DigestAuthenticator.java in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 uses Catalina as the hard-coded server secret (aka private key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging knowledge of this string, a different vulnerability than CVE-2011-1184.
OSV
Use of Hard-coded Cryptographic Key in Apache Tomcat
osv·2022-05-14·CVSS 5.0
CVE-2011-5064 [MEDIUM] Use of Hard-coded Cryptographic Key in Apache Tomcat
Use of Hard-coded Cryptographic Key in Apache Tomcat
DigestAuthenticator.java in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 uses Catalina as the hard-coded server secret (aka private key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging knowledge of this string, a different vulnerability than CVE-2011-1184.
GHSA
Use of Hard-coded Cryptographic Key in Apache Tomcat
ghsa·2022-05-14·CVSS 5.0
CVE-2011-5064 [MEDIUM] CWE-321 Use of Hard-coded Cryptographic Key in Apache Tomcat
Use of Hard-coded Cryptographic Key in Apache Tomcat
DigestAuthenticator.java in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 uses Catalina as the hard-coded server secret (aka private key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging knowledge of this string, a different vulnerability than CVE-2011-1184.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-5064 tomcat: Hard-coded server secret eases bypass of cryptographic protection mechanisms
bugzilla·2012-01-16·CVSS 4.3
CVE-2011-5064 [MEDIUM] CVE-2011-5064 tomcat: Hard-coded server secret eases bypass of cryptographic protection mechanisms
CVE-2011-5064 tomcat: Hard-coded server secret eases bypass of cryptographic protection mechanisms
DigestAuthenticator.java in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 uses Catalina as the hard-coded server secret (aka private key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging knowledge of this string.
References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-5064
Discussion:
*** This bug has been marked as a duplicate of bug 741401 ***
Bugzilla
CVE-2011-1184 CVE-2011-5062 CVE-2011-5063 CVE-2011-5064 tomcat: Multiple weaknesses in HTTP DIGEST authentication
bugzilla·2011-09-26·CVSS 5.0
CVE-2011-1184 [MEDIUM] CVE-2011-1184 CVE-2011-5062 CVE-2011-5063 CVE-2011-5064 tomcat: Multiple weaknesses in HTTP DIGEST authentication
CVE-2011-1184 CVE-2011-5062 CVE-2011-5063 CVE-2011-5064 tomcat: Multiple weaknesses in HTTP DIGEST authentication
Multiple security flaws were found in the Apache Tomcat HTTP DIGEST (RFC 2069) Authentication implementation:
* it was possible to perform session reply attacks,
* server generated nonce-values were not checked,
* count of client generated nonce-values were not checked,
* quality of protection (qop) values were not checked,
* realms values were not checked,
* a known, hard-coded string was used as server secret.
References:
[1] http://tomcat.apache.org/security-5.html
[2] http://tomcat.apache.org/security-6.html
[3] http://www.securityfocus.com/archive/1/519818/30/0/threaded
Relevant upstream patches:
[4] http://svn.apache.org/viewvc?view=revision&revision=1158180
(for Tomca
Bugzilla
CVE-2009-5064 glibc: ldd unexpected code execution issue [rhel-6.2]
bugzilla·2011-06-14·CVSS 6.9
CVE-2009-5064 [MEDIUM] CVE-2009-5064 glibc: ldd unexpected code execution issue [rhel-6.2]
CVE-2009-5064 glibc: ldd unexpected code execution issue [rhel-6.2]
Don't include me in crap like that. There is no problem. This is people making crap up.
Discussion:
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For information on the advisory, and where to find the updated
files, follow the link below.
If the solution does not work for you, open a new bug report.
http://rhn.redhat.com/errata/RHSA-2011-1526.html
http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-02/msg00006.htmlhttp://marc.info/?l=bugtraq&m=139344343412337&w=2http://rhn.redhat.com/errata/RHSA-2012-0074.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0075.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0076.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0077.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0078.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0325.htmlhttp://secunia.com/advisories/57126http://svn.apache.org/viewvc?view=rev&rev=1087655http://svn.apache.org/viewvc?view=rev&rev=1158180http://svn.apache.org/viewvc?view=rev&rev=1159309http://tomcat.apache.org/security-5.htmlhttp://tomcat.apache.org/security-6.htmlhttp://tomcat.apache.org/security-7.htmlhttp://www.debian.org/security/2012/dsa-2401http://www.redhat.com/support/errata/RHSA-2011-1845.htmlhttps://lists.apache.org/thread.html/06cfb634bc7bf37af7d8f760f118018746ad8efbd519c4b789ac9c2e%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/8dcaf7c3894d66cb717646ea1504ea6e300021c85bb4e677dc16b1aa%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r3aacc40356defc3f248aa504b1e48e819dd0471a0a83349080c6bcbf%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r584a714f141eff7b1c358d4679288177bd4ca4558e9999d15867d4b5%40%3Cdev.tomcat.apache.org%3Ehttp://lists.opensuse.org/opensuse-security-announce/2012-02/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-02/msg00006.htmlhttp://marc.info/?l=bugtraq&m=139344343412337&w=2http://rhn.redhat.com/errata/RHSA-2012-0074.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0075.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0076.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0077.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0078.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0325.htmlhttp://secunia.com/advisories/57126http://svn.apache.org/viewvc?view=rev&rev=1087655http://svn.apache.org/viewvc?view=rev&rev=1158180http://svn.apache.org/viewvc?view=rev&rev=1159309http://tomcat.apache.org/security-5.htmlhttp://tomcat.apache.org/security-6.htmlhttp://tomcat.apache.org/security-7.htmlhttp://www.debian.org/security/2012/dsa-2401http://www.redhat.com/support/errata/RHSA-2011-1845.htmlhttps://lists.apache.org/thread.html/06cfb634bc7bf37af7d8f760f118018746ad8efbd519c4b789ac9c2e%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/8dcaf7c3894d66cb717646ea1504ea6e300021c85bb4e677dc16b1aa%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r3aacc40356defc3f248aa504b1e48e819dd0471a0a83349080c6bcbf%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r584a714f141eff7b1c358d4679288177bd4ca4558e9999d15867d4b5%40%3Cdev.tomcat.apache.org%3E
2012-01-14
Published