CVE Database
/

CVE-2016-0762

Back to search

CVE-2016-0762

Published: Aug 10, 2017

Modified: Sep 17, 2024

PUBLISHED

Description

The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not process the supplied password if the supplied user name did not exist. This made a timing attack possible to determine valid user names. Note that the default configuration includes the LockOutRealm which makes exploitation of this vulnerability harder.

VendorProductVersions

Apache Software Foundation

Apache Tomcat

affected
9.0.0.M1 to 9.0.0.M9
affected
8.5.0 to 8.5.4
affected
8.0.0.RC1 to 8.0.36
affected
7.0.0 to 7.0.70
affected
6.0.0 to 6.0.45

References

1037144
vdb-entry
x_refsource_SECTRACK
RHSA-2017:2247
vendor-advisory
x_refsource_REDHAT
RHSA-2017:0457
vendor-advisory
x_refsource_REDHAT
RHSA-2017:0455
vendor-advisory
x_refsource_REDHAT
93939
vdb-entry
x_refsource_BID
DSA-3720
vendor-advisory
x_refsource_DEBIAN
RHSA-2017:0456
vendor-advisory
x_refsource_REDHAT
USN-4557-1
vendor-advisory
x_refsource_UBUNTU

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now