LWN.net Logo

tomcat: authentication bypass

Package(s):tomcat CVE #(s):CVE-2011-3190
Created:October 17, 2011 Updated:February 2, 2012
Description: From the CVE entry:

Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other versions allow remote attackers to spoof AJP requests, bypass authentication, and obtain sensitive information by causing the connector to interpret a request body as a new request.

Alerts:
CentOS CESA-2011:1780 2011-12-22
Scientific Linux SL-tomc-20111205 2011-12-05
Oracle ELSA-2011-1780 2011-12-05
Red Hat RHSA-2011:1780-01 2011-12-05
Ubuntu USN-1252-1 2011-11-08
Fedora FEDORA-2011-13457 2011-09-29
Mandriva MDVSA-2011:156 2011-10-18
openSUSE openSUSE-SU-2011:1134-1 2011-10-17
Debian DSA-2401-1 2012-02-02

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds