CVE-2011-5064: Medium severity tomcat vulnerability
DigestAuthenticator.java in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 uses Catalina as the hard-coded server secret (aka private key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging knowledge of this string, a different vulnerability than CVE-2011-1184.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-5064?
CVE-2011-5064 is classified as a high severity vulnerability due to the risk of unauthorized access.
How do I fix CVE-2011-5064?
To fix CVE-2011-5064, upgrade to Apache Tomcat versions 5.5.34, 6.0.33, or 7.0.12 or later.
What versions of Apache Tomcat are affected by CVE-2011-5064?
CVE-2011-5064 affects Apache Tomcat versions 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12.
What kind of attacks can exploit CVE-2011-5064?
CVE-2011-5064 can be exploited by attackers to bypass cryptographic protection mechanisms.
Is CVE-2011-5064 specific to a certain environment?
CVE-2011-5064 is specifically related to the HTTP Digest Access Authentication implementation in Apache Tomcat.