CVE-2010-1157
The MITRE CVE dictionary describes this issue as:
Find out more about CVE-2010-1157 from the MITRE CVE dictionary dictionary and NIST NVD.
Statement
The risks associated with fixing this flaw are greater than the low severity security risk. We therefore have no plans to fix this flaw. The information leak can be avoided by adjusting the configuration to always specify a realm-name.
CVSS v2 metrics
| Base Score | 2.6 |
|---|---|
| Base Metrics | AV:N/AC:H/Au:N/C:P/I:N/A:N |
| Access Vector | Network |
| Access Complexity | High |
| Authentication | None |
| Confidentiality Impact | Partial |
| Integrity Impact | None |
| Availability Impact | None |
Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).
Red Hat Security Errata
| Platform | Errata | Release Date |
|---|---|---|
| Red Hat JBoss Web Server 1.0 for RHEL 4 AS | RHSA-2011:0897 | 2011-06-22 |
| Red Hat JBoss Enterprise Application Platform 4.2.0 for RHEL 5 Server (jbossweb) | RHSA-2010:0584 | 2010-08-02 |
| Red Hat JBoss Enterprise Application Platform 4.3.0 for RHEL 4 AS (jbossweb) | RHSA-2010:0584 | 2010-08-02 |
| Red Hat JBoss Web Server 1.0 | RHSA-2011:0896 | 2011-06-22 |
| Red Hat JBoss Enterprise Web Server 1 for RHEL 6 Server | RHSA-2011:0897 | 2011-06-22 |
| Red Hat JBoss Enterprise Application Platform 4.2.0 for RHEL 4 AS (jbossweb) | RHSA-2010:0584 | 2010-08-02 |
| Red Hat JBoss Enterprise Web Server 1 for RHEL 5 Server | RHSA-2011:0897 | 2011-06-22 |
| Red Hat JBoss Enterprise Application Platform 4.3.0 for RHEL 5 Server (jbossweb) | RHSA-2010:0584 | 2010-08-02 |
Affected Packages State
| Platform | Package | State |
|---|---|---|
| Red Hat Satellite 5.3 | tomcat5 | Will not fix |
| Red Hat Satellite 5.2 | tomcat5 | Will not fix |
| Red Hat Satellite 5.1 | tomcat5 | Will not fix |
| Red Hat Satellite 5.0 | tomcat5 | Will not fix |
| Red Hat Enterprise Linux 6 | tomcat6 | Will not fix |
| Red Hat Enterprise Linux 5 | tomcat5 | Will not fix |
| Red Hat Certificate System 7.3 for 4AS | Tomcat | Will not fix |
| Red Hat Certificate System 7.2 for 4AS | Tomcat | Will not fix |
CVE description copyright © 2017, The MITRE Corporation
