Beveiligingsadvies

CVE-2011-5062

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2012-01-14 21:00:00
Laatst bijgewerkt 2024-08-07 00:23:39
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qop values, which might allow remote attackers to bypass intended integrity-protection requirements via a qop=auth value, a different vulnerability than CVE-2011-1184.