CVE-2009-0580

Impact:
Low
Public Date:
2009-06-03
Bugzilla:
503978: CVE-2009-0580 tomcat6 Information disclosure in authentication classes

The MITRE CVE dictionary describes this issue as:

Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, allows remote attackers to enumerate valid usernames via requests to /j_security_check with malformed URL encoding of passwords, related to improper error checking in the (1) MemoryRealm, (2) DataSourceRealm, and (3) JDBCRealm authentication realms, as demonstrated by a % (percent) value for the j_password parameter.

Find out more about CVE-2009-0580 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v2 metrics

Base Score 5
Base Metrics AV:N/AC:L/Au:N/C:P/I:N/A:N
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact None
Availability Impact None

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat Satellite 5.2 (RHEL v.4 AS) (tomcat5) RHSA-2009:1616 2009-11-30
Red Hat Certificate System 7.3 for 4AS RHSA-2010:0602 2010-08-04
Red Hat Satellite 5.3 (RHEL v.4) (tomcat5) RHSA-2009:1616 2009-11-30
Red Hat JBoss Enterprise Application Platform 4.3.0 for RHEL 4 AS RHSA-2009:1146 2009-07-06
Red Hat JBoss Enterprise Application Platform 4.2.0 for RHEL 4 AS RHSA-2009:1144 2009-07-06
Red Hat JBoss Enterprise Application Platform 4.3.0 for RHEL 5 Server RHSA-2009:1145 2009-07-06
Red Hat JBoss Enterprise Application Platform 4.2.0 for RHEL 5 Server RHSA-2009:1143 2009-07-06
Red Hat Developer Suite v.3 (AS v.4) (tomcat5) RHSA-2009:1563 2009-11-09
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 Server (tomcat5) RHSA-2009:1454 2009-09-21
Red Hat JBoss Web Server 1.0 for RHEL 4 AS (tomcat5) RHSA-2009:1454 2009-09-21
Red Hat JBoss Web Server 1.0 for RHEL 4 AS (tomcat6) RHSA-2009:1506 2009-10-14
Red Hat Application Server v2 4AS (tomcat5) RHSA-2009:1562 2009-11-09
Red Hat Enterprise Linux 5 (tomcat5) RHSA-2009:1164 2009-07-21
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 Server (tomcat6) RHSA-2009:1506 2009-10-14

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.