Posted by Mark Thomas on Jun 27
CVE-2011-2204 Apache Tomcat information disclosure
Severity: Low
Vendor: The Apache Software Foundation
Versions Affected:
– Tomcat 7.0.0 to 7.0.16
– Tomcat 6.0.0 to 6.0.32
– Tomcat 5.5.0 to 5.5.33
Earlier, unsupported versions may also be affected
Description:
When using the MemoryUserDatabase (based on tomcat-users.xml) and
creating users via JMX, an exception during the user creation process
may trigger an error message in the JMX client…
Source: [SECURITY] CVE-2011-2204 – Apache Tomcat information disclosure




