[SECURITY] CVE-2011-2204 – Apache Tomcat information disclosure

0
47

Posted by Mark Thomas on Jun 27

CVE-2011-2204 Apache Tomcat information disclosure

Severity: Low
Vendor: The Apache Software Foundation

Versions Affected:
– Tomcat 7.0.0 to 7.0.16
– Tomcat 6.0.0 to 6.0.32
– Tomcat 5.5.0 to 5.5.33
Earlier, unsupported versions may also be affected

Description:
When using the MemoryUserDatabase (based on tomcat-users.xml) and
creating users via JMX, an exception during the user creation process
may trigger an error message in the JMX client…

Source: [SECURITY] CVE-2011-2204 – Apache Tomcat information disclosure