CVE-2016-0762

The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not process the supplied password if the supplied user name did not exist. This made a timing attack possible to determine valid user names. Note that the default configuration includes the LockOutRealm which makes exploitation of this vulnerability harder.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
apacheCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
VendorProductVersion
apachetomcat
6.0.0 ≤
𝑥
≤ 6.0.45
apachetomcat
7.0.0 ≤
𝑥
≤ 7.0.70
apachetomcat
8.0 ≤
𝑥
≤ 8.0.36
apachetomcat
8.5.0 ≤
𝑥
≤ 8.5.4
apachetomcat
9.0.0:milestone1
apachetomcat
9.0.0:milestone2
apachetomcat
9.0.0:milestone3
apachetomcat
9.0.0:milestone4
apachetomcat
9.0.0:milestone5
apachetomcat
9.0.0:milestone6
apachetomcat
9.0.0:milestone7
apachetomcat
9.0.0:milestone8
apachetomcat
9.0.0:milestone9
canonicalubuntu_linux
16.04
debiandebian_linux
8.0
redhatjboss_enterprise_web_server
3.0.0
redhatenterprise_linux_desktop
7.0
redhatenterprise_linux_eus
7.4
redhatenterprise_linux_eus
7.5
redhatenterprise_linux_eus
7.6
redhatenterprise_linux_eus
7.7
redhatenterprise_linux_server
7.0
redhatenterprise_linux_server_aus
7.4
redhatenterprise_linux_server_aus
7.6
redhatenterprise_linux_server_aus
7.7
redhatenterprise_linux_server_tus
7.6
redhatenterprise_linux_server_tus
7.7
redhatenterprise_linux_workstation
7.0
netapponcommand_insight
-
netapponcommand_shift
-
netappsnap_creator_framework
-
oraclecommunications_diameter_signaling_router
8.0.0 ≤
𝑥
≤ 8.5.0
oracletekelec_platform_distribution
7.4.0 ≤
𝑥
≤ 7.7.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
tomcat6
focal
dne
cosmic
dne
bionic
dne
artful
dne
zesty
dne
yakkety
dne
xenial
Fixed 6.0.45+dfsg-1ubuntu0.1
released
trusty
Fixed 6.0.39-1ubuntu0.1
released
precise
Fixed 6.0.35-1ubuntu3.9
released
tomcat7
focal
dne
cosmic
not-affected
bionic
not-affected
artful
ignored
zesty
ignored
yakkety
ignored
xenial
Fixed 7.0.68-1ubuntu0.3
released
trusty
not-affected
precise
ignored
tomcat8
focal
dne
cosmic
not-affected
bionic
not-affected
artful
not-affected
zesty
not-affected
yakkety
not-affected
xenial
Fixed 8.0.32-1ubuntu1.3
released
trusty
dne
precise
dne
References