CVE-2010-1157
Description
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — http://www.vupen.com/english/advisories/2010/3056
Vendor advisory: secalert@redhat.com — http://www.vupen.com/english/advisories/2010/0980
Vendor advisory: secalert@redhat.com — http://tomcat.apache.org/security-6.html
Vendor advisory: secalert@redhat.com — http://tomcat.apache.org/security-5.html
Vendor advisory: secalert@redhat.com — http://svn.apache.org/viewvc?view=revision&revision=936541
Vendor advisory: secalert@redhat.com — http://svn.apache.org/viewvc?view=revision&revision=936540
Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/43310
Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/42368
Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/39574
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Maven | org.apache.tomcat:tomcat | >=5.5.0,<5.5.30 | 5.5.30 |
| Maven | org.apache.tomcat:tomcat | >=6.0.0,<6.0.28 | 6.0.28 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| apache | tomcat | 6.0.0 | |
| apache | tomcat | 5.5.0 | |
| apache | tomcat | 5.5.1 | |
| apache | tomcat | 5.5.2 | |
| apache | tomcat | 5.5.3 | |
| apache | tomcat | 5.5.4 | |
| apache | tomcat | 5.5.5 | |
| apache | tomcat | 5.5.6 | |
| apache | tomcat | 5.5.7 | |
| apache | tomcat | 5.5.8 | |
| apache | tomcat | 5.5.9 | |
| apache | tomcat | 5.5.10 | |
| apache | tomcat | 5.5.11 | |
| apache | tomcat | 5.5.12 | |
| apache | tomcat | 5.5.13 | |
| apache | tomcat | 5.5.14 | |
| apache | tomcat | 5.5.15 | |
| apache | tomcat | 5.5.16 | |
| apache | tomcat | 5.5.17 | |
| apache | tomcat | 5.5.18 | |
| apache | tomcat | 5.5.19 | |
| apache | tomcat | 5.5.20 | |
| apache | tomcat | 5.5.21 | |
| apache | tomcat | 5.5.22 | |
| apache | tomcat | 5.5.23 | |
| apache | tomcat | 5.5.24 | |
| apache | tomcat | 5.5.25 | |
| apache | tomcat | 5.5.26 | |
| apache | tomcat | 5.5.27 | |
| apache | tomcat | 5.5.28 | |
| apache | tomcat | 5.5.29 | |
| apache | tomcat | 6.0.1 | |
| apache | tomcat | 6.0.2 | |
| apache | tomcat | 6.0.3 | |
| apache | tomcat | 6.0.4 | |
| apache | tomcat | 6.0.5 | |
| apache | tomcat | 6.0.6 | |
| apache | tomcat | 6.0.7 | |
| apache | tomcat | 6.0.8 | |
| apache | tomcat | 6.0.9 | |
| apache | tomcat | 6.0.10 | |
| apache | tomcat | 6.0.11 | |
| apache | tomcat | 6.0.12 | |
| apache | tomcat | 6.0.13 | |
| apache | tomcat | 6.0.14 | |
| apache | tomcat | 6.0.15 | |
| apache | tomcat | 6.0.16 | |
| apache | tomcat | 6.0.17 | |
| apache | tomcat | 6.0.18 | |
| apache | tomcat | 6.0.19 | |
| apache | tomcat | 6.0.20 | |
| apache | tomcat | 6.0.24 | |
| apache | tomcat | 6.0.26 | |
References
- http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html
- http://marc.info/?l=bugtraq&m=129070310906557&w=2
- http://marc.info/?l=bugtraq&m=133469267822771&w=2
- http://marc.info/?l=bugtraq&m=136485229118404&w=2
- http://marc.info/?l=bugtraq&m=139344343412337&w=2
- http://secunia.com/advisories/39574
- http://secunia.com/advisories/42368
- http://secunia.com/advisories/43310
- http://secunia.com/advisories/57126
- http://support.apple.com/kb/HT5002
- http://svn.apache.org/viewvc?view=revision&revision=936540
- http://svn.apache.org/viewvc?view=revision&revision=936541
- http://tomcat.apache.org/security-5.html
- http://tomcat.apache.org/security-6.html
- http://www.debian.org/security/2011/dsa-2207
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:176
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:177
- http://www.redhat.com/support/errata/RHSA-2011-0896.html
- http://www.redhat.com/support/errata/RHSA-2011-0897.html
- http://www.securityfocus.com/archive/1/510879/100/0/threaded
- http://www.securityfocus.com/archive/1/516397/100/0/threaded
- http://www.securityfocus.com/bid/39635
- http://www.vmware.com/security/advisories/VMSA-2011-0003.html
- http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html
CWEs
CWE-200
Verify integrity in audit chain (admin only). AS-IS.