CVE-2011-5062: Medium severity tomcat vulnerability
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qop values, which might allow remote attackers to bypass intended integrity-protection requirements via a qop=auth value, a different vulnerability than CVE-2011-1184.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-5062?
CVE-2011-5062 has a moderate severity rating that allows potential integrity protection bypass.
How do I fix CVE-2011-5062?
To remediate CVE-2011-5062, upgrade to Apache Tomcat version 5.5.34, 6.0.33, or 7.0.12 or later.
Which versions of Apache Tomcat are affected by CVE-2011-5062?
CVE-2011-5062 affects Apache Tomcat versions 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12.
What type of vulnerability is CVE-2011-5062?
CVE-2011-5062 is an authentication-related vulnerability related to improper handling of qop values.
Can CVE-2011-5062 be exploited remotely?
Yes, CVE-2011-5062 can be exploited remotely, enabling attackers to bypass intended integrity-protection requirements.