CVE-2016-0762: Medium severity Apache Tomcat vulnerability
Last updated 25 August 2025
Other sources
The following flaw was found in Tomcat:
The Realm implementations did not process the supplied password if the supplied user name did not exist. This made a timing attack possible to determine valid user names. Note that the default configuration includes the LockOutRealm which makes exploitation of this vulnerability harder.
Upstream patches:
6.0.47: https://svn.apache.org/viewvc?view=revision&revision=1758506 7.0.72: https://svn.apache.org/viewvc?view=revision&revision=1758502 8.5.5: https://svn.apache.org/viewvc?view=revision&revision=1758500 8.0.37: https://svn.apache.org/viewvc?view=revision&revision=1758501
External References:
https://tomcat.apache.org/security-6.html#FixedinApacheTomcat6.0.47 https://tomcat.apache.org/security-7.html#FixedinApacheTomcat7.0.72 https://tomcat.apache.org/security-8.html#FixedinApacheTomcat8.5.5and8.0.37
— Red Hat
The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0. ...
— Debian
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 6.0.47 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 7.0.72 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 8.5.5 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 8.0.37 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcatto a version that resolves this vulnerability.Fixed in 6.0.46 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcatto a version that resolves this vulnerability.Fixed in 7.0.72 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcatto a version that resolves this vulnerability.Fixed in 8.0.37 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcatto a version that resolves this vulnerability.Fixed in 8.5.5 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcatto a version that resolves this vulnerability.Fixed in 9.0.0.M10 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 6.0.47 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 7.0.72 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 8.0.37 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 8.5.5
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0762?
CVE-2016-0762 is classified as a medium severity vulnerability due to its potential for timing attacks to disclose valid usernames.
How do I fix CVE-2016-0762?
To fix CVE-2016-0762, upgrade to Apache Tomcat versions 6.0.47, 7.0.72, 8.0.37, 8.5.5, or later.
What software is affected by CVE-2016-0762?
CVE-2016-0762 affects multiple versions of Apache Tomcat, including versions 6.x, 7.x, 8.x, and 9.0.0-milestone releases.
What type of vulnerability is CVE-2016-0762?
CVE-2016-0762 is a timing attack vulnerability affecting the authentication process in Apache Tomcat's Realm implementations.
Is there a workaround for CVE-2016-0762?
There are no specific workarounds for CVE-2016-0762, but upgrading to a patched version is the recommended mitigation.