Oval Definition:oval:org.mitre.oval:def:14931
Revision Date:2015-04-20Version:28
Title:HP-UX Apache Running Tomcat Servlet Engine, Remote Information Disclosure, Authentication Bypass, Cross-Site Scripting (XSS), Unauthorized Access, Denial of Service (DoS)
Description:Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.17, when the MemoryUserDatabase is used, creates log entries containing passwords upon encountering errors in JMX user creation, which allows local users to obtain sensitive information by reading a log file.
Family:unixClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2011-2204
Platform(s):HP-UX 11
Product(s):
Definition Synopsis
  • platforms
  • HP-UX B.11.23
  • OR HP-UX B.11.31
  • AND hpuxws22TOMCAT.TOMCAT version is less than B.5.5.34.01
  • BACK