CVE-2010-1157: Infoleak
Apache Tomcat 5.5.0 through 5.5.29 and 6.0.0 through 6.0.26 might allow remote attackers to discover the server's hostname or IP address by sending a request for a resource that requires (1) BASIC or (2) DIGEST authentication, and then reading the realm field in the WWW-Authenticate header in the reply.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1157?
CVE-2010-1157 is considered a low severity vulnerability that allows potential information disclosure.
How do I fix CVE-2010-1157?
To mitigate CVE-2010-1157, upgrade Apache Tomcat to version 5.5.30 or later, or 6.0.27 or later.
What types of authentication does CVE-2010-1157 affect?
CVE-2010-1157 affects resources protected by BASIC and DIGEST authentication methods in Apache Tomcat.
Who is primarily affected by CVE-2010-1157?
Administrators using Apache Tomcat versions 5.5.0 to 5.5.29 and 6.0.0 to 6.0.26 may be affected by CVE-2010-1157.
Can CVE-2010-1157 lead to unauthorized access?
While CVE-2010-1157 does not provide direct unauthorized access, it can help an attacker discover the server's hostname or IP address.