CVE-2011-5063: Medium severity tomcat vulnerability
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check realm values, which might allow remote attackers to bypass intended access restrictions by leveraging the availability of a protection space with weaker authentication or authorization requirements, a different vulnerability than CVE-2011-1184.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-5063?
CVE-2011-5063 has a moderate severity rating allowing attackers to bypass access restrictions in affected versions of Apache Tomcat.
How do I fix CVE-2011-5063?
To fix CVE-2011-5063, upgrade to Apache Tomcat versions 5.5.34, 6.0.33, or 7.0.12 or later.
Which versions of Apache Tomcat are affected by CVE-2011-5063?
CVE-2011-5063 affects Apache Tomcat versions 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12.
What does CVE-2011-5063 exploit in Apache Tomcat?
CVE-2011-5063 exploits a weakness in the HTTP Digest Access Authentication implementation by not checking realm values.
Can CVE-2011-5063 be exploited remotely?
Yes, CVE-2011-5063 can be exploited remotely, allowing attackers to potentially gain unauthorized access to protected resources.