CVE-2016-0762Medium· 5.9▾ SunlitThe Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not process the supplied password if the supplied user name did not exist. This made a…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 1.6 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
8.0%
The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not process the supplied password if the supplied user name did not exist. This made a timing attack possible to determine valid user names. Note that the default configuration includes the LockOutRealm which makes exploitation of this vulnerability harder.
tomcat >= 6.0.0, <= 6.0.45tomcat >= 7.0.0, <= 7.0.70tomcat >= 8.0, <= 8.0.36tomcat >= 8.5.0, <= 8.5.4tomcat = 9.0.0ubuntu_linux = 16.04debian_linux = 8.0jboss_enterprise_web_server = 3.0.0enterprise_linux_desktop = 7.0enterprise_linux_eus = 7.4enterprise_linux_eus = 7.5enterprise_linux_eus = 7.6enterprise_linux_eus = 7.7enterprise_linux_server = 7.0enterprise_linux_server_aus = 7.4enterprise_linux_server_aus = 7.6enterprise_linux_server_aus = 7.7enterprise_linux_server_tus = 7.6enterprise_linux_server_tus = 7.7enterprise_linux_workstation = 7.0oncommand_insightoncommand_shiftsnap_creator_frameworkcommunications_diameter_signaling_router >= 8.0.0, <= 8.5.0tekelec_platform_distribution >= 7.4.0, <= 7.7.1Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2016-5018Critical· 9.1In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able to bypass a configured SecurityManager via a Tomcat utility method that was accessible t…
CVE-2016-6797High· 7.5The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global JNDI resources to those resources expli…
CVE-2016-6796High· 7.5A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via manipulation of the configuration par…
CVE-2021-30640Medium· 6.5A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm
CVE-2021-33037Medium· 5.3Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse pr…
CVE-2021-25329High· 7.0The fix for CVE-2020-9484 was incomplete