ID

VAR-201201-0259


CVE

CVE-2011-4858


TITLE

Hash table implementations vulnerable to algorithmic complexity attacks

Trust: 0.8

sources: CERT/CC: VU#903934

DESCRIPTION

Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters. Some programming language implementations do not sufficiently randomize their hash functions or provide means to limit key collision attacks, which can be leveraged by an unauthenticated attacker to cause a denial-of-service (DoS) condition. Apache Tomcat Calculates the hash value of the form parameter without restricting the assumption of hash collision. (CPU Resource consumption ) There is a vulnerability that becomes a condition.A third party can send a large amount of crafted parameters to disrupt service operation. (CPU Resource consumption ) There is a possibility of being put into a state. ---------------------------------------------------------------------- Secunia is hiring! Find your next job here: http://secunia.com/company/jobs/ ---------------------------------------------------------------------- TITLE: Hitachi COBOL2002 Products Unspecified Vulnerability SECUNIA ADVISORY ID: SA47643 VERIFY ADVISORY: Secunia.com http://secunia.com/advisories/47643/ Customer Area (Credentials Required) https://ca.secunia.com/?page=viewadvisory&vuln_id=47643 RELEASE DATE: 2012-01-20 DISCUSS ADVISORY: http://secunia.com/advisories/47643/#comments AVAILABLE ON SITE AND IN CUSTOMER AREA: * Last Update * Popularity * Comments * Criticality Level * Impact * Where * Solution Status * Operating System / Software * CVE Reference(s) http://secunia.com/advisories/47643/ ONLY AVAILABLE IN CUSTOMER AREA: * Authentication Level * Report Reliability * Secunia PoC * Secunia Analysis * Systems Affected * Approve Distribution * Remediation Status * Secunia CVSS Score * CVSS https://ca.secunia.com/?page=viewadvisory&vuln_id=47643 ONLY AVAILABLE WITH SECUNIA CSI AND SECUNIA PSI: * AUTOMATED SCANNING http://secunia.com/vulnerability_scanning/personal/ http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/ DESCRIPTION: Hitachi has reported a vulnerability in some COBOL2002 products, which can be exploited by malicious users to compromise a vulnerable system. SOLUTION: Upgrade to version 02-01-/D. PROVIDED AND/OR DISCOVERED BY: Reported by the vendor. ORIGINAL ADVISORY: http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS12-002/index.html OTHER REFERENCES: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ DEEP LINKS: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED DESCRIPTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED SOLUTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXPLOIT: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help private users keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ---------------------------------------------------------------------- . Release Date: 2012-02-06 Last Updated: 2012-03-05 ------------------------------------------------------------------------------- Potential Security Impact: Remote Denial of Service (DoS), access restriction bypass Source: Hewlett-Packard Company, HP Software Security Response Team VULNERABILITY SUMMARY Potential security vulnerabilities have been identified with HP-UX Apache Running Tomcat Servlet Engine. These vulnerabilities could be exploited remotely to create a Denial of Service (DoS) or to perform an access restriction bypass. References: CVE-2006-7243, CVE-2011-4858, CVE-2011-4885, CVE-2012-0022 SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed. HP-UX B.11.23, B.11.31 running HP-UX Apache Web Server Suite v3.21 or earlier BACKGROUND CVSS 2.0 Base Metrics =========================================================== Reference Base Vector Base Score CVE-2006-7243 (AV:N/AC:L/Au:N/C:N/I:P/A:N) 5.0 CVE-2011-4858 (AV:N/AC:L/Au:N/C:N/I:N/A:P) 5.0 CVE-2011-4885 (AV:N/AC:L/Au:N/C:N/I:N/A:P) 5.0 CVE-2012-0022 (AV:N/AC:L/Au:N/C:N/I:N/A:P) 5.0 =========================================================== Information on CVSS is documented in HP Customer Notice: HPSN-2008-002 RESOLUTION HP has provided the following software updates to resolve the vulnerability. The updates are available for download from https://h20392.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=HPUXWSATW322 Note: HP-UX Web Server Suite v3.22 contains HP-UX Tomcat-based Servlet Engine v5.5.35.01 Web Server Suite Version Apache Depot Name HP-UX Web Server Suite v.3.22 HP-UX B.11.23 HPUXWS22ATW-B322-64.depot HP-UX B.11.23 HPUXWS22ATW-B322-32.depot HP-UX B.11.31 HPUXWS22ATW-B322-64.depot HP-UX B.11.31 HPUXWS22ATW-B322-32.depot MANUAL ACTIONS: Yes - Update Install HP-UX Web Server Suite v3.22 or subsequent PRODUCT SPECIFIC INFORMATION HP-UX Software Assistant: HP-UX Software Assistant is an enhanced application that replaces HP-UX Security Patch Check. It analyzes all Security Bulletins issued by HP and lists recommended actions that may apply to a specific HP-UX system. It can also download patches and create a depot automatically. For more information see https://www.hp.com/go/swa The following text is for use by the HP-UX Software Assistant. AFFECTED VERSIONS HP-UX Web Server Suite HP-UX B.11.23 HP-UX B.11.31 ================== hpuxws22TOMCAT.TOMCAT action: install revision B.5.5.35.01 or subsequent hpuxws22APCH32.APACHE hpuxws22APCH32.APACHE2 hpuxws22APCH32.AUTH_LDAP hpuxws22APCH32.AUTH_LDAP2 hpuxws22APCH32.MOD_JK hpuxws22APCH32.MOD_JK2 hpuxws22APCH32.MOD_PERL hpuxws22APCH32.MOD_PERL2 hpuxws22APCH32.PHP hpuxws22APCH32.PHP2 hpuxws22APCH32.WEBPROXY action: install revision B.2.2.15.11 or subsequent END AFFECTED VERSION HISTORY Version:1 (rev.1) - 06 February 2012 Initial release Version:2 (rev.2) - 05 March 2012 Revised location of depots Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy. Support: For issues about implementing the recommendations of this Security Bulletin, contact normal HP Services support channel. For other issues about the content of this Security Bulletin, send e-mail to security-alert@hp.com. Report: To report a potential security vulnerability with any HP supported product, send Email to: security-alert@hp.com Subscribe: To initiate a subscription to receive future HP Security Bulletin alerts via Email: http://h41183.www4.hp.com/signup_alerts.php?jumpid=hpsc_secbulletins Security Bulletin List: A list of HP Security Bulletins, updated periodically, is contained in HP Security Notice HPSN-2011-001: https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay/?docId=emr_na-c02964430 Security Bulletin Archive: A list of recently released Security Bulletins is available here: http://h20566.www2.hp.com/portal/site/hpsc/public/kb/secBullArchive/ Software Product Category: The Software Product Category is represented in the title by the two characters following HPSB. 3C = 3COM 3P = 3rd Party Software GN = HP General Software HF = HP Hardware and Firmware MP = MPE/iX MU = Multi-Platform Software NS = NonStop Servers OV = OpenVMS PI = Printing and Imaging PV = ProCurve ST = Storage Software TU = Tru64 UNIX UX = HP-UX Copyright 2012 Hewlett-Packard Development Company, L.P. Hewlett-Packard Company shall not be liable for technical or editorial errors or omissions contained herein. The information provided is provided "as is" without warranty of any kind. To the extent permitted by law, neither HP or its affiliates, subcontractors or suppliers will be liable for incidental,special or consequential damages including downtime cost; lost profits;damages relating to the procurement of substitute products or services; or damages for loss of data, or software restoration. Hewlett-Packard Company and the names of Hewlett-Packard products referenced herein are trademarks of Hewlett-Packard Company in the United States and other countries. Other product and company names mentioned herein may be trademarks of their respective owners. Description: JBoss Operations Network (JBoss ON) is a middleware management solution that provides a single point of control to deploy, manage, and monitor JBoss Enterprise Middleware, applications, and services. The Release Notes will be available shortly from https://docs.redhat.com/docs/en-US/index.html The following security issues are also fixed with this release: JBoss ON did not properly verify security tokens, allowing an unapproved agent to connect as an approved agent. As a result, the attacker could retrieve sensitive data about the server the hijacked agent was running on, including JMX credentials. (CVE-2012-0052) JBoss ON sometimes allowed agent registration to succeed when the registration request did not include a security token. This is a feature designed to add convenience. A remote attacker could use this flaw to spoof the identity of an approved agent and pass a null security token, allowing them to hijack the approved agent's session, and steal its security token. As a result, the attacker could retrieve sensitive data about the server the hijacked agent was running on, including JMX credentials. (CVE-2012-0062) A flaw was found in the way LDAP (Lightweight Directory Access Protocol) authentication was handled. If the LDAP bind account credentials became invalid, subsequent log in attempts with any password for user accounts created via LDAP were successful. (CVE-2011-4858) It was found that after installing the remote client (by extracting rhq-remoting-cli-[version].zip), its root directory had world read, write, and execute permissions. This allowed the attributes of the child directories and their files to be modified. A local attacker could use this flaw to steal the JBoss ON credentials of a user running the remote client, or trick them into running arbitrary code. The remote client is typically used by privileged JBoss ON users. Bugs fixed (http://bugzilla.redhat.com/): 750521 - CVE-2011-4858 tomcat: hash table collisions CPU usage DoS (oCERT-2011-003) 772514 - CVE-2012-0032 JON CLI: world-writable root directory 781964 - CVE-2012-0052 JON: Unapproved agents can connect using the name of an existing approved agent 783008 - CVE-2012-0062 JON: Unapproved agents can hijack an approved agent's endpoint by using a null security token 799789 - CVE-2012-1100 JON: LDAP authentication allows any user access if bind credentials are bad 5. If JBoss Web was hosting an application with UTF-8 character encoding enabled, or that included user-supplied UTF-8 strings in a response, a remote attacker could use this flaw to cause a denial of service (infinite loop) on the JBoss Web server. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: tomcat5 security and bug fix update Advisory ID: RHSA-2012:0680-01 Product: JBoss Enterprise Web Server Advisory URL: https://rhn.redhat.com/errata/RHSA-2012-0680.html Issue date: 2012-05-21 CVE Names: CVE-2011-1184 CVE-2011-2204 CVE-2011-2526 CVE-2011-3190 CVE-2011-4858 CVE-2011-5062 CVE-2011-5063 CVE-2011-5064 CVE-2012-0022 ===================================================================== 1. Summary: Updated tomcat5 packages that fix multiple security issues and two bugs are now available for JBoss Enterprise Web Server 1.0.2 for Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this update as having moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: JBoss Enterprise Web Server 1.0 for RHEL 5 Server - noarch JBoss Enterprise Web Server 1.0 for RHEL 6 Server - noarch 3. Description: Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies. JBoss Enterprise Web Server includes the Tomcat Native library, providing Apache Portable Runtime (APR) support for Tomcat. References in this text to APR refer to the Tomcat Native implementation, not any other apr package. This update includes bug fixes as documented in JBPAPP-4873 and JBPAPP-6133. It also resolves the following security issues: Multiple flaws were found in the way Tomcat handled HTTP DIGEST authentication. These flaws weakened the Tomcat HTTP DIGEST authentication implementation, subjecting it to some of the weaknesses of HTTP BASIC authentication, for example, allowing remote attackers to perform session replay attacks. (CVE-2011-1184, CVE-2011-5062, CVE-2011-5063, CVE-2011-5064) A flaw was found in the way the Coyote (org.apache.coyote.ajp.AjpProcessor) and APR (org.apache.coyote.ajp.AjpAprProcessor) Tomcat AJP (Apache JServ Protocol) connectors processed certain POST requests. An attacker could send a specially-crafted request that would cause the connector to treat the message body as a new request. This allows arbitrary AJP messages to be injected, possibly allowing an attacker to bypass a web application's authentication checks and gain access to information they would otherwise be unable to access. The JK (org.apache.jk.server.JkCoyoteHandler) connector is used by default when the APR libraries are not present. The JK connector is not affected by this flaw. (CVE-2011-3190) It was found that the Java hashCode() method implementation was susceptible to predictable hash collisions. This update introduces a limit on the number of parameters processed per request to mitigate this issue. The default limit is 512 for parameters and 128 for headers. These defaults can be changed by setting the org.apache.tomcat.util.http.Parameters.MAX_COUNT and org.apache.tomcat.util.http.MimeHeaders.MAX_COUNT system properties. (CVE-2011-4858) It was found that Tomcat did not handle large numbers of parameters and large parameter values efficiently. A remote attacker could make Tomcat use an excessive amount of CPU time by sending an HTTP request containing a large number of parameters or large parameter values. This update introduces limits on the number of parameters and headers processed per request to address this issue. Refer to the CVE-2011-4858 description for information about the org.apache.tomcat.util.http.Parameters.MAX_COUNT and org.apache.tomcat.util.http.MimeHeaders.MAX_COUNT system properties. (CVE-2012-0022) A flaw was found in the Tomcat MemoryUserDatabase. If a runtime exception occurred when creating a new user with a JMX client, that user's password was logged to Tomcat log files. Note: By default, only administrators have access to such log files. (CVE-2011-2204) A flaw was found in the way Tomcat handled sendfile request attributes when using the HTTP APR or NIO (Non-Blocking I/O) connector. A malicious web application running on a Tomcat instance could use this flaw to bypass security manager restrictions and gain access to files it would otherwise be unable to access, or possibly terminate the Java Virtual Machine (JVM). The HTTP NIO connector is used by default in JBoss Enterprise Web Server. (CVE-2011-2526) Red Hat would like to thank oCERT for reporting CVE-2011-4858, and the Apache Tomcat project for reporting CVE-2011-2526. oCERT acknowledges Julian Wälde and Alexander Klink as the original reporters of CVE-2011-4858. Users of Tomcat should upgrade to these updated packages, which resolve these issues. Tomcat must be restarted for this update to take effect. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/knowledge/articles/11258 5. Bugs fixed (http://bugzilla.redhat.com/): 717013 - CVE-2011-2204 tomcat: password disclosure vulnerability 720948 - CVE-2011-2526 tomcat: security manager restrictions bypass 734868 - CVE-2011-3190 tomcat: authentication bypass and information disclosure 741401 - CVE-2011-1184 CVE-2011-5062 CVE-2011-5063 CVE-2011-5064 tomcat: Multiple weaknesses in HTTP DIGEST authentication 750521 - CVE-2011-4858 tomcat: hash table collisions CPU usage DoS (oCERT-2011-003) 783359 - CVE-2012-0022 tomcat: large number of parameters DoS 6. Package List: JBoss Enterprise Web Server 1.0 for RHEL 5 Server: Source: tomcat5-5.5.33-27_patch_07.ep5.el5.src.rpm noarch: tomcat5-5.5.33-27_patch_07.ep5.el5.noarch.rpm tomcat5-admin-webapps-5.5.33-27_patch_07.ep5.el5.noarch.rpm tomcat5-common-lib-5.5.33-27_patch_07.ep5.el5.noarch.rpm tomcat5-jasper-5.5.33-27_patch_07.ep5.el5.noarch.rpm tomcat5-jasper-eclipse-5.5.33-27_patch_07.ep5.el5.noarch.rpm tomcat5-jasper-javadoc-5.5.33-27_patch_07.ep5.el5.noarch.rpm tomcat5-jsp-2.0-api-5.5.33-27_patch_07.ep5.el5.noarch.rpm tomcat5-jsp-2.0-api-javadoc-5.5.33-27_patch_07.ep5.el5.noarch.rpm tomcat5-parent-5.5.33-27_patch_07.ep5.el5.noarch.rpm tomcat5-server-lib-5.5.33-27_patch_07.ep5.el5.noarch.rpm tomcat5-servlet-2.4-api-5.5.33-27_patch_07.ep5.el5.noarch.rpm tomcat5-servlet-2.4-api-javadoc-5.5.33-27_patch_07.ep5.el5.noarch.rpm tomcat5-webapps-5.5.33-27_patch_07.ep5.el5.noarch.rpm JBoss Enterprise Web Server 1.0 for RHEL 6 Server: Source: tomcat5-5.5.33-28_patch_07.ep5.el6.src.rpm noarch: tomcat5-5.5.33-28_patch_07.ep5.el6.noarch.rpm tomcat5-admin-webapps-5.5.33-28_patch_07.ep5.el6.noarch.rpm tomcat5-common-lib-5.5.33-28_patch_07.ep5.el6.noarch.rpm tomcat5-jasper-5.5.33-28_patch_07.ep5.el6.noarch.rpm tomcat5-jasper-eclipse-5.5.33-28_patch_07.ep5.el6.noarch.rpm tomcat5-jasper-javadoc-5.5.33-28_patch_07.ep5.el6.noarch.rpm tomcat5-jsp-2.0-api-5.5.33-28_patch_07.ep5.el6.noarch.rpm tomcat5-jsp-2.0-api-javadoc-5.5.33-28_patch_07.ep5.el6.noarch.rpm tomcat5-parent-5.5.33-28_patch_07.ep5.el6.noarch.rpm tomcat5-server-lib-5.5.33-28_patch_07.ep5.el6.noarch.rpm tomcat5-servlet-2.4-api-5.5.33-28_patch_07.ep5.el6.noarch.rpm tomcat5-servlet-2.4-api-javadoc-5.5.33-28_patch_07.ep5.el6.noarch.rpm tomcat5-webapps-5.5.33-28_patch_07.ep5.el6.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 7. References: https://www.redhat.com/security/data/cve/CVE-2011-1184.html https://www.redhat.com/security/data/cve/CVE-2011-2204.html https://www.redhat.com/security/data/cve/CVE-2011-2526.html https://www.redhat.com/security/data/cve/CVE-2011-3190.html https://www.redhat.com/security/data/cve/CVE-2011-4858.html https://www.redhat.com/security/data/cve/CVE-2011-5062.html https://www.redhat.com/security/data/cve/CVE-2011-5063.html https://www.redhat.com/security/data/cve/CVE-2011-5064.html https://www.redhat.com/security/data/cve/CVE-2012-0022.html https://access.redhat.com/security/updates/classification/#moderate http://tomcat.apache.org/security-5.html https://issues.jboss.org/browse/JBPAPP-4873 https://issues.jboss.org/browse/JBPAPP-6133 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2012 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFPunk6XlSAg2UNWIIRAsSqAJwLQ4FFNNQ5OlLMGPoZ8bJzpsF0+QCfV6o2 fAcxCwlEL1EiCUlsTZu7Li4= =Gucp -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce . Description: JBoss Enterprise Portal Platform is the open source implementation of the Java EE suite of services and Portal services running atop JBoss Enterprise Application Platform. It comprises a set of offerings for enterprise customers who are looking for pre-configured profiles of JBoss Enterprise Middleware components that have been tested and certified together to provide an integrated experience. This JBoss Enterprise Portal Platform 4.3 CP07 release serves as a replacement for JBoss Enterprise Portal Platform 4.3 CP06. The following security fixes are also included: JBoss Seam 2 did not properly block access to JBoss Expression Language (EL) constructs in page exception handling, allowing arbitrary Java methods to be executed. Note: A properly configured and enabled Java Security Manager would prevent exploitation of this flaw. (CVE-2011-1484) Note: If you have created custom applications that are packaged with a copy of the JBoss Seam 2 library, those applications must be rebuilt with the updated jboss-seam.jar file provided by this update. (CVE-2011-1184, CVE-2011-5062, CVE-2011-5063, CVE-2011-5064) The invoker servlets, deployed by default via httpha-invoker, only performed access control on the HTTP GET and POST methods, allowing remote attackers to make unauthenticated requests by using different HTTP methods. Due to the second layer of authentication provided by a security interceptor, this issue is not exploitable on default installations unless an administrator has misconfigured the security interceptor or disabled it. Note that if you have created custom applications that are packaged with a copy of the JBoss Seam 2 library, those applications must be rebuilt with the updated jboss-seam.jar file provided by this update. Relevant releases/architectures: RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 3. 5 client): Source: ftp://ftp.redhat.com/pub/redhat/linux/enterprise/5Client/en/os/SRPMS/tomcat5-5.5.23-0jpp.31.el5_8.src.rpm i386: tomcat5-debuginfo-5.5.23-0jpp.31.el5_8.i386.rpm tomcat5-jsp-2.0-api-5.5.23-0jpp.31.el5_8.i386.rpm tomcat5-servlet-2.4-api-5.5.23-0jpp.31.el5_8.i386.rpm x86_64: tomcat5-debuginfo-5.5.23-0jpp.31.el5_8.x86_64.rpm tomcat5-jsp-2.0-api-5.5.23-0jpp.31.el5_8.x86_64.rpm tomcat5-servlet-2.4-api-5.5.23-0jpp.31.el5_8.x86_64.rpm RHEL Desktop Workstation (v. (CVE-2011-3190) A flaw in the way Tomcat recycled objects that contain data from user requests (such as IP addresses and HTTP headers) when certain errors occurred. If a user sent a request that caused an error to be logged, Tomcat would return a reply to the next request (which could be sent by a different user) with data from the first user's request, leading to information disclosure. Under certain conditions, a remote attacker could leverage this flaw to hijack sessions. The References section of this erratum contains a download link (you must log in to download the update). Before applying the update, back up your existing JBoss Enterprise Web Server installation (including all applications and configuration files)

Trust: 3.42

sources: NVD: CVE-2011-4858 // CERT/CC: VU#903934 // JVNDB: JVNDB-2012-001003 // VULMON: CVE-2011-4858 // PACKETSTORM: 121037 // PACKETSTORM: 108860 // PACKETSTORM: 110540 // PACKETSTORM: 112907 // PACKETSTORM: 109271 // PACKETSTORM: 111010 // PACKETSTORM: 110084 // PACKETSTORM: 112904 // PACKETSTORM: 109367 // PACKETSTORM: 111782 // PACKETSTORM: 112908

AFFECTED PRODUCTS

vendor:apachemodel:tomcatscope:eqversion:5.5.35

Trust: 1.6

vendor:apachemodel:tomcatscope:eqversion:6.0.6

Trust: 1.6

vendor:apachemodel:tomcatscope:eqversion:6.0.0

Trust: 1.6

vendor:apachemodel:tomcatscope:eqversion:6.0.1

Trust: 1.6

vendor:apachemodel:tomcatscope:eqversion:6.0.2

Trust: 1.6

vendor:apachemodel:tomcatscope:eqversion:6.0.4

Trust: 1.6

vendor:apachemodel:tomcatscope:eqversion:6.0.5

Trust: 1.6

vendor:apachemodel:tomcatscope:eqversion:6.0.3

Trust: 1.6

vendor:apachemodel:tomcatscope:eqversion:6.0.7

Trust: 1.6

vendor:apachemodel:tomcatscope:eqversion:6.0.8

Trust: 1.6

vendor:apachemodel:tomcatscope:eqversion:7.0.11

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.8

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.16

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.24

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.21

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.11

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.22

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.14

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.31

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.33

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.10

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.17

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.20

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.19

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.18

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.14

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.3

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.0

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.5

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.7

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.29

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.12

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.2

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.1

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.34

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.26

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.9

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.16

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.19

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.9

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.12

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.15

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.13

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.13

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.18

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.22

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.32

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.23

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.25

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.10

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.21

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.28

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.30

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.15

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.4

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.6

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.17

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.27

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.20

Trust: 1.0

vendor:apache tomcatmodel: - scope: - version: -

Trust: 0.8

vendor:microsoftmodel: - scope: - version: -

Trust: 0.8

vendor:oraclemodel: - scope: - version: -

Trust: 0.8

vendor:rubymodel: - scope: - version: -

Trust: 0.8

vendor:the php groupmodel: - scope: - version: -

Trust: 0.8

vendor:fujitsumodel:interstage list worksscope: - version: -

Trust: 0.8

vendor:fujitsumodel:interstage service integratorscope: - version: -

Trust: 0.8

vendor:hitachimodel:cosminexus studioscope:eqversion:version 5

Trust: 0.8

vendor:hitachimodel:ucosminexus developerscope:eqversion:st ard

Trust: 0.8

vendor:fujitsumodel:systemwalker software configuration managerscope: - version: -

Trust: 0.8

vendor:fujitsumodel:systemwalker it change managerscope: - version: -

Trust: 0.8

vendor:hitachimodel:cosminexus application serverscope:eqversion:enterprise version 6

Trust: 0.8

vendor:fujitsumodel:interstage xml business activity recorderscope: - version: -

Trust: 0.8

vendor:necmodel:webotx application serverscope:eqversion:st ard-j edition v7.1 to v8.1

Trust: 0.8

vendor:apachemodel:tomcatscope:ltversion:7.x

Trust: 0.8

vendor:fujitsumodel:interstage web serverscope: - version: -

Trust: 0.8

vendor:necmodel:webotxscope:eqversion:enterprise service bus v6.4 to v8.4

Trust: 0.8

vendor:necmodel:webotxscope:eqversion:enterprise edition v4.1 to v6.5

Trust: 0.8

vendor:hitachimodel:ucosminexus servicescope:eqversion:platform

Trust: 0.8

vendor:hitachimodel:ucosminexus application serverscope:eqversion:smart edition

Trust: 0.8

vendor:hitachimodel:it operations analyzerscope: - version: -

Trust: 0.8

vendor:apachemodel:tomcatscope:ltversion:6.x

Trust: 0.8

vendor:hitachimodel:ucosminexus developerscope:eqversion:professional for plug-in

Trust: 0.8

vendor:hitachimodel:cosminexus component containerscope: - version: -

Trust: 0.8

vendor:fujitsumodel:systemwalker operation managerscope: - version: -

Trust: 0.8

vendor:fujitsumodel:systemwalker it process masterscope: - version: -

Trust: 0.8

vendor:necmodel:webotxscope:eqversion:developer v7.1 to v8.1

Trust: 0.8

vendor:fujitsumodel:interstage application development cycle managerscope: - version: -

Trust: 0.8

vendor:fujitsumodel:interstage application serverscope:eqversion:none

Trust: 0.8

vendor:necmodel:webotxscope:eqversion:portal v8.2 to v8.3

Trust: 0.8

vendor:necmodel:webotx application serverscope:eqversion:enterprise edition v7.1 to v8.1

Trust: 0.8

vendor:necmodel:csviewscope:eqversion:/faq navigator v4 v5

Trust: 0.8

vendor:necmodel:webotx application serverscope:eqversion:enterprise v8.2 to v8.4

Trust: 0.8

vendor:hitachimodel:ucosminexus application serverscope:eqversion:st ard-r

Trust: 0.8

vendor:necmodel:webotx application serverscope:eqversion:foundation v8.2 to v8.4

Trust: 0.8

vendor:necmodel:webotxscope:eqversion:sip application server st ard edition v7.1 to v8.1

Trust: 0.8

vendor:necmodel:webotxscope:eqversion:development environment v6.1 to v6.5

Trust: 0.8

vendor:fujitsumodel:systemwalker desktop inspectionscope: - version: -

Trust: 0.8

vendor:apachemodel:tomcatscope:eqversion:6.0.35

Trust: 0.8

vendor:necmodel:websam storage vmware vcenter plug-inscope:eqversion:v1.1

Trust: 0.8

vendor:necmodel:webotx application serverscope:eqversion:web edition v7.1 to v8.1

Trust: 0.8

vendor:fujitsumodel:success serverscope: - version: -

Trust: 0.8

vendor:fujitsumodel:interstage application serverscope:eqversion:plus developer / apworks / studio

Trust: 0.8

vendor:fujitsumodel:systemwalker service quality coordinatorscope: - version: -

Trust: 0.8

vendor:necmodel:webotxscope:eqversion:uddi registry v1.1 to v7.1

Trust: 0.8

vendor:fujitsumodel:systemwalker runbook automationscope: - version: -

Trust: 0.8

vendor:fujitsumodel:serverviewscope:eqversion:resource orchestrator cloud edition

Trust: 0.8

vendor:necmodel:webotx application serverscope:eqversion:st ard v8.2 to v8.4

Trust: 0.8

vendor:hitachimodel:ucosminexus primary serverscope:eqversion:base

Trust: 0.8

vendor:hitachimodel:cosminexus developerscope:eqversion:professional version 6

Trust: 0.8

vendor:fujitsumodel:interstage list managerscope: - version: -

Trust: 0.8

vendor:necmodel:webotxscope:eqversion:st ard-j edition v4.1 to v6.5

Trust: 0.8

vendor:hitachimodel:cosminexus primary serverscope:eqversion:base

Trust: 0.8

vendor:fujitsumodel:interstage business application serverscope: - version: -

Trust: 0.8

vendor:necmodel:infoframe documentskipperscope:eqversion:v4.1

Trust: 0.8

vendor:necmodel:infocagescope:eqversion:pc security v1.44 before

Trust: 0.8

vendor:hitachimodel:ucosminexus servicescope:eqversion:architect

Trust: 0.8

vendor:necmodel:webotxscope:eqversion:st ard edition v4.1 to v6.5

Trust: 0.8

vendor:fujitsumodel:internet navigware serverscope: - version: -

Trust: 0.8

vendor:hitachimodel:cosminexus developerscope:eqversion:version 5

Trust: 0.8

vendor:hitachimodel:ucosminexus application serverscope:eqversion:express

Trust: 0.8

vendor:hitachimodel:ucosminexus application serverscope:eqversion:light

Trust: 0.8

vendor:necmodel:infoframe documentskipperscope:eqversion:v3.2

Trust: 0.8

vendor:hitachimodel:ucosminexus application serverscope:eqversion:enterprise

Trust: 0.8

vendor:necmodel:websam securemasterscope:eqversion:enterpriseidentitymanager ver4.1 all versions up to

Trust: 0.8

vendor:hitachimodel:ucosminexus developerscope:eqversion:01

Trust: 0.8

vendor:fujitsumodel:interstage application framework suitescope: - version: -

Trust: 0.8

vendor:fujitsumodel:systemwalker availability viewscope: - version: -

Trust: 0.8

vendor:fujitsumodel:interstage shunsaku data managerscope: - version: -

Trust: 0.8

vendor:hitachimodel:cosminexus application serverscope:eqversion:version 5

Trust: 0.8

vendor:fujitsumodel:interstage form coordinator workflowscope: - version: -

Trust: 0.8

vendor:fujitsumodel:systemwalker service catalog managerscope: - version: -

Trust: 0.8

vendor:necmodel:webotxscope:eqversion:web edition v4.1 to v6.5

Trust: 0.8

vendor:necmodel:webotx application serverscope:eqversion:st ard edition v7.1 to v8.1

Trust: 0.8

vendor:hitachimodel:cosminexus developerscope:eqversion:st ard version 6

Trust: 0.8

vendor:hitachimodel:ucosminexus developerscope:eqversion:light

Trust: 0.8

vendor:necmodel:websam securemasterscope:eqversion:enterpriseaccessmanager ver5.0 to ver6.1

Trust: 0.8

vendor:hitachimodel:ucosminexus application serverscope:eqversion:st ard

Trust: 0.8

vendor:hitachimodel:cosminexus developerscope:eqversion:light version 6

Trust: 0.8

vendor:necmodel:webotx application serverscope:eqversion:express v8.2 to v8.4

Trust: 0.8

vendor:apachemodel:tomcatscope:eqversion:7.0.23

Trust: 0.8

vendor:hitachimodel:ucosminexus developerscope:eqversion:professional

Trust: 0.8

vendor:hitachimodel:cosminexus application serverscope:eqversion:st ard version 6

Trust: 0.8

vendor:cybozumodel:garoonscope:eqversion:2.0.0 to 3.1

Trust: 0.8

vendor:hitachimodel:ucosminexus servicescope:eqversion:platform - messaging

Trust: 0.8

vendor:necmodel:infoframe documentskipperscope:eqversion:v5.1

Trust: 0.8

vendor:fujitsumodel:interstage job workload serverscope: - version: -

Trust: 0.8

sources: CERT/CC: VU#903934 // JVNDB: JVNDB-2012-001003 // CNNVD: CNNVD-201201-056 // NVD: CVE-2011-4858

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2011-4858
value: MEDIUM

Trust: 1.0

CARNEGIE MELLON: VU#903934
value: 10.80

Trust: 0.8

NVD: CVE-2011-4858
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201201-056
value: MEDIUM

Trust: 0.6

VULMON: CVE-2011-4858
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2011-4858
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

sources: CERT/CC: VU#903934 // VULMON: CVE-2011-4858 // JVNDB: JVNDB-2012-001003 // CNNVD: CNNVD-201201-056 // NVD: CVE-2011-4858

PROBLEMTYPE DATA

problemtype:CWE-399

Trust: 1.8

sources: JVNDB: JVNDB-2012-001003 // NVD: CVE-2011-4858

THREAT TYPE

remote

Trust: 1.0

sources: PACKETSTORM: 109271 // PACKETSTORM: 110084 // PACKETSTORM: 111782 // PACKETSTORM: 112908 // CNNVD: CNNVD-201201-056

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-201201-056

CONFIGURATIONS

sources: JVNDB: JVNDB-2012-001003

EXPLOIT AVAILABILITY

sources: VULMON: CVE-2011-4858

PATCH

title:Changelogurl:http://tomcat.apache.org/tomcat-7.0-doc/changelog.html

Trust: 0.8

title:HS12-019url:http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS12-019/index.html

Trust: 0.8

title:HS12-003url:http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS12-003/index.html

Trust: 0.8

title:1626697url:http://www-01.ibm.com/support/docview.wss?uid=swg21626697

Trust: 0.8

title:4034373url:http://www-01.ibm.com/support/docview.wss?uid=swg24034373

Trust: 0.8

title:NV12-003url:http://www.nec.co.jp/security-info/secinfo/nv12-003.html

Trust: 0.8

title:Bug 750521url:https://bugzilla.redhat.com/show_bug.cgi?id=750521

Trust: 0.8

title:Multiple vulnerabilities in Oracle Java Web Console - oracle_javaurl:https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_oracle_java

Trust: 0.8

title:Multiple vulnerabilities in Oracle Java Web Console - oracle_java1url:https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_oracle_java1

Trust: 0.8

title:Multiple Denial of Service (DoS) vulnerabilities in Apache Tomcaturl:https://blogs.oracle.com/sunsecurity/entry/multiple_denial_of_service_dos

Trust: 0.8

title:CY12-02-006url:http://cs.cybozu.co.jp/information/20120224up08.php

Trust: 0.8

title:interstage_as_201201url:http://software.fujitsu.com/jp/security/products-fujitsu/solution/interstage_as_201201.html

Trust: 0.8

title:HS12-019url:http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/HS12-019/index.html

Trust: 0.8

title:HS12-003url:http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/HS12-003/index.html

Trust: 0.8

title:【iStorage Mシリーズ】WebSAM Storage VMware vCenter Plug-inV1.1が使用しているApache Tomcat脆弱性問題の対処についてurl:http://www.support.nec.co.jp/View.aspx?id=3140100906

Trust: 0.8

title:WebOTX Webコンテナ のハッシュに関する脆弱性(CVE-2011-4858)についてurl:https://www.support.nec.co.jp/View.aspx?id=3010100358

Trust: 0.8

title:InfoCage PCセキュリティ - 重要なお知らせurl:http://www.nec.co.jp/cced/infocage/info/pc_security_news120329.html

Trust: 0.8

title:Red Hat: Moderate: tomcat6 security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20120475 - Security Advisory

Trust: 0.1

title:Red Hat: Moderate: tomcat5 security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20120474 - Security Advisory

Trust: 0.1

title:Red Hat: Important: jbossweb security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20120074 - Security Advisory

Trust: 0.1

title:Red Hat: Important: jbossweb security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20120076 - Security Advisory

Trust: 0.1

title:Ubuntu Security Notice: tomcat6 vulnerabilitiesurl:https://vulmon.com/vendoradvisory?qidtp=ubuntu_security_notice&qid=USN-1359-1

Trust: 0.1

title:Red Hat: Moderate: tomcat5 security and bug fix updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20120680 - Security Advisory

Trust: 0.1

title:Red Hat: Moderate: tomcat6 security and bug fix updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20120682 - Security Advisory

Trust: 0.1

title: - url:https://github.com/Live-Hack-CVE/CVE-2011-4084

Trust: 0.1

sources: VULMON: CVE-2011-4858 // JVNDB: JVNDB-2012-001003

EXTERNAL IDS

db:NVDid:CVE-2011-4858

Trust: 3.5

db:CERT/CCid:VU#903934

Trust: 3.3

db:OCERTid:OCERT-2011-003

Trust: 2.5

db:SECUNIAid:48791

Trust: 1.1

db:SECUNIAid:48790

Trust: 1.1

db:SECUNIAid:48549

Trust: 1.1

db:SECUNIAid:54971

Trust: 1.1

db:SECUNIAid:55115

Trust: 1.1

db:BIDid:51200

Trust: 1.1

db:JVNDBid:JVNDB-2012-001003

Trust: 0.8

db:MLISTid:[ANNOUNCE] 20111228 [SECURITY] APACHE TOMCAT AND THE HASHTABLE COLLISION DOS VULNERABILITY

Trust: 0.6

db:CNNVDid:CNNVD-201201-056

Trust: 0.6

db:SECUNIAid:47643

Trust: 0.2

db:EXPLOIT-DBid:2012

Trust: 0.1

db:VULMONid:CVE-2011-4858

Trust: 0.1

db:PACKETSTORMid:121037

Trust: 0.1

db:HITACHIid:HS12-002

Trust: 0.1

db:PACKETSTORMid:108860

Trust: 0.1

db:PACKETSTORMid:110540

Trust: 0.1

db:PACKETSTORMid:112907

Trust: 0.1

db:PACKETSTORMid:109271

Trust: 0.1

db:PACKETSTORMid:111010

Trust: 0.1

db:PACKETSTORMid:110084

Trust: 0.1

db:PACKETSTORMid:112904

Trust: 0.1

db:PACKETSTORMid:109367

Trust: 0.1

db:PACKETSTORMid:111782

Trust: 0.1

db:PACKETSTORMid:112908

Trust: 0.1

sources: CERT/CC: VU#903934 // VULMON: CVE-2011-4858 // PACKETSTORM: 121037 // PACKETSTORM: 108860 // PACKETSTORM: 110540 // PACKETSTORM: 112907 // PACKETSTORM: 109271 // PACKETSTORM: 111010 // PACKETSTORM: 110084 // PACKETSTORM: 112904 // PACKETSTORM: 109367 // PACKETSTORM: 111782 // PACKETSTORM: 112908 // JVNDB: JVNDB-2012-001003 // CNNVD: CNNVD-201201-056 // NVD: CVE-2011-4858

REFERENCES

url:http://www.ocert.org/advisories/ocert-2011-003.html

Trust: 2.5

url:http://www.nruns.com/_downloads/advisory28122011.pdf

Trust: 2.5

url:http://www.kb.cert.org/vuls/id/903934

Trust: 2.5

url:https://bugzilla.redhat.com/show_bug.cgi?id=750521

Trust: 1.7

url:http://tomcat.apache.org/tomcat-7.0-doc/changelog.html

Trust: 1.7

url:http://rhn.redhat.com/errata/rhsa-2012-0406.html

Trust: 1.2

url:http://rhn.redhat.com/errata/rhsa-2012-0075.html

Trust: 1.2

url:http://rhn.redhat.com/errata/rhsa-2012-0325.html

Trust: 1.2

url:https://github.com/firefart/hashcollision-dos-poc/blob/master/hashtablepoc.py

Trust: 1.1

url:http://marc.info/?l=bugtraq&m=132871655717248&w=2

Trust: 1.1

url:http://www.debian.org/security/2012/dsa-2401

Trust: 1.1

url:http://secunia.com/advisories/48791

Trust: 1.1

url:http://secunia.com/advisories/48790

Trust: 1.1

url:http://marc.info/?l=bugtraq&m=136485229118404&w=2

Trust: 1.1

url:http://secunia.com/advisories/54971

Trust: 1.1

url:http://secunia.com/advisories/55115

Trust: 1.1

url:http://rhn.redhat.com/errata/rhsa-2012-0089.html

Trust: 1.1

url:http://rhn.redhat.com/errata/rhsa-2012-0074.html

Trust: 1.1

url:http://rhn.redhat.com/errata/rhsa-2012-0076.html

Trust: 1.1

url:http://rhn.redhat.com/errata/rhsa-2012-0078.html

Trust: 1.1

url:http://rhn.redhat.com/errata/rhsa-2012-0077.html

Trust: 1.1

url:http://www.securityfocus.com/bid/51200

Trust: 1.1

url:https://oval.cisecurity.org/repository/search/definition/oval%3aorg.mitre.oval%3adef%3a18886

Trust: 1.1

url:http://secunia.com/advisories/48549

Trust: 1.1

url:http://marc.info/?l=bugtraq&m=133294394108746&w=2

Trust: 1.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-4858

Trust: 1.0

url:http://mail-archives.apache.org/mod_mbox/tomcat-announce/201112.mbox/%3c4efb9800.5010106%40apache.org%3e

Trust: 1.0

url:http://www.cs.rice.edu/~scrosby/hash/crosbywallach_usenixsec2003.pdf

Trust: 0.8

url:http://technet.microsoft.com/en-us/security/bulletin/ms11-100.mspx

Trust: 0.8

url:http://blogs.technet.com/b/srd/archive/2011/12/27/more-information-about-the-december-2011-asp-net-vulnerability.aspx

Trust: 0.8

url:http://blade.nagaokaut.ac.jp/cgi-bin/scat.rb/ruby/ruby-talk/391606

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2012-0022

Trust: 0.8

url:https://www.redhat.com/security/data/cve/cve-2011-4858.html

Trust: 0.8

url:https://access.redhat.com/security/team/contact/

Trust: 0.8

url:https://www.redhat.com/mailman/listinfo/rhsa-announce

Trust: 0.8

url:http://bugzilla.redhat.com/):

Trust: 0.8

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2011-4858

Trust: 0.8

url:http://www.ipa.go.jp/security/ciadr/vul/20120106-web.html

Trust: 0.8

url:http://jvn.jp/cert/jvnvu903934

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2011-4858

Trust: 0.8

url:http://mail-archives.apache.org/mod_mbox/tomcat-announce/201112.mbox/%3c4efb9800.5010106@apache.org%3e

Trust: 0.7

url:https://nvd.nist.gov/vuln/detail/cve-2011-2526

Trust: 0.7

url:https://nvd.nist.gov/vuln/detail/cve-2011-1184

Trust: 0.7

url:https://www.redhat.com/security/data/cve/cve-2011-5063.html

Trust: 0.6

url:https://www.redhat.com/security/data/cve/cve-2012-0022.html

Trust: 0.6

url:https://www.redhat.com/security/data/cve/cve-2011-2526.html

Trust: 0.6

url:https://nvd.nist.gov/vuln/detail/cve-2011-5063

Trust: 0.6

url:https://www.redhat.com/security/data/cve/cve-2011-5064.html

Trust: 0.6

url:https://www.redhat.com/security/data/cve/cve-2011-1184.html

Trust: 0.6

url:https://nvd.nist.gov/vuln/detail/cve-2011-5064

Trust: 0.6

url:https://www.redhat.com/security/data/cve/cve-2011-5062.html

Trust: 0.6

url:https://nvd.nist.gov/vuln/detail/cve-2011-5062

Trust: 0.6

url:https://nvd.nist.gov/vuln/detail/cve-2011-2204

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2011-3190

Trust: 0.4

url:https://access.redhat.com/security/updates/classification/#moderate

Trust: 0.4

url:https://access.redhat.com/security/updates/classification/#important

Trust: 0.4

url:https://www.redhat.com/security/data/cve/cve-2011-2204.html

Trust: 0.3

url:https://www.redhat.com/security/data/cve/cve-2011-3190.html

Trust: 0.3

url:https://issues.jboss.org/browse/jbpapp-6133

Trust: 0.3

url:https://issues.jboss.org/browse/jbpapp-4873

Trust: 0.3

url:http://tomcat.apache.org/security-5.html

Trust: 0.3

url:http://h20566.www2.hp.com/portal/site/hpsc/public/kb/secbullarchive/

Trust: 0.2

url:http://h41183.www4.hp.com/signup_alerts.php?jumpid=hpsc_secbulletins

Trust: 0.2

url:https://www.hp.com/go/swa

Trust: 0.2

url:https://access.redhat.com/jbossnetwork/restricted/listsoftware.html?product=webserver&downloadtype=securitypatches&version=1.0.2

Trust: 0.2

url:https://www.redhat.com/security/data/cve/cve-2011-4610.html

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2011-4610

Trust: 0.2

url:https://docs.redhat.com/docs/en-us/index.html

Trust: 0.2

url:https://access.redhat.com/security/team/key/#package

Trust: 0.2

url:https://cwe.mitre.org/data/definitions/399.html

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2012:0475

Trust: 0.1

url:https://github.com/live-hack-cve/cve-2011-4084

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://usn.ubuntu.com/1359-1/

Trust: 0.1

url:https://www.exploit-db.com/exploits/2012/

Trust: 0.1

url:http://tools.cisco.com/security/center/viewalert.x?alertid=24901

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2009-0033

Trust: 0.1

url:https://h20392.www2.hp.com/portal

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2009-3548

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2009-2902

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-3718

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2009-0580

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2009-2693

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2009-0781

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-2227

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-4476

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2008-5515

Trust: 0.1

url:https://h20566.www2.hp.com/portal/site/hpsc/public/kb/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2009-0783

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-5885

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-0013

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-1157

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-2729

Trust: 0.1

url:http://www.hitachi.co.jp/prod/comp/soft1/global/security/info/vuls/hs12-002/index.html

Trust: 0.1

url:https://ca.secunia.com/?page=viewadvisory&vuln_id=47643

Trust: 0.1

url:http://secunia.com/company/jobs/

Trust: 0.1

url:http://secunia.com/advisories/47643/#comments

Trust: 0.1

url:http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/

Trust: 0.1

url:http://secunia.com/vulnerability_intelligence/

Trust: 0.1

url:http://secunia.com/advisories/secunia_security_advisories/

Trust: 0.1

url:http://secunia.com/advisories/47643/

Trust: 0.1

url:http://secunia.com/vulnerability_scanning/personal/

Trust: 0.1

url:http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

Trust: 0.1

url:http://secunia.com/advisories/about_secunia_advisories/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-4885

Trust: 0.1

url:https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docdisplay/?docid=emr_na-c02964430

Trust: 0.1

url:https://h20392.www2.hp.com/portal/swdepot/displayproductinfo.do?productnumber=hpuxwsatw322

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2006-7243

Trust: 0.1

url:https://rhn.redhat.com/errata/rhsa-2012-0679.html

Trust: 0.1

url:https://access.redhat.com/jbossnetwork/restricted/listsoftware.html?product=appplatform&downloadtype=securitypatches&version=5.1.2

Trust: 0.1

url:https://www.redhat.com/security/data/cve/cve-2012-0052.html

Trust: 0.1

url:https://www.redhat.com/security/data/cve/cve-2012-1100.html

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-0062

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-0052

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-1100

Trust: 0.1

url:https://www.redhat.com/security/data/cve/cve-2012-0032.html

Trust: 0.1

url:https://access.redhat.com/jbossnetwork/restricted/listsoftware.html?downloadtype=distributions&product=em&version=3.0.1

Trust: 0.1

url:https://www.redhat.com/security/data/cve/cve-2012-0062.html

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-0032

Trust: 0.1

url:https://access.redhat.com/jbossnetwork/restricted/listsoftware.html?product=brms&downloadtype=securitypatches&version=5.2.0

Trust: 0.1

url:https://access.redhat.com/jbossnetwork/restricted/listsoftware.html?product=soaplatform&downloadtype=securitypatches&version=5.2.0+ga

Trust: 0.1

url:https://access.redhat.com/jbossnetwork/restricted/listsoftware.html?product=jbportal&downloadtype=securitypatches&version=5.2.0

Trust: 0.1

url:https://rhn.redhat.com/errata/rhsa-2012-0680.html

Trust: 0.1

url:https://access.redhat.com/knowledge/articles/11258

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-4085

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-1484

Trust: 0.1

url:https://access.redhat.com/jbossnetwork/restricted/listsoftware.html?downloadtype=distributions&product=jbportal&version=4.3+cp07

Trust: 0.1

url:https://www.redhat.com/security/data/cve/cve-2011-1484.html

Trust: 0.1

url:https://rhn.redhat.com/errata/rhsa-2012-0091.html

Trust: 0.1

url:https://www.redhat.com/security/data/cve/cve-2011-4085.html

Trust: 0.1

url:https://rhn.redhat.com/errata/rhsa-2012-0474.html

Trust: 0.1

url:https://access.redhat.com/kb/docs/doc-11259

Trust: 0.1

url:https://issues.jboss.org/browse/jbpapp-6852

Trust: 0.1

url:https://www.redhat.com/security/data/cve/cve-2011-3375.html

Trust: 0.1

url:https://rhn.redhat.com/errata/rhsa-2012-0681.html

Trust: 0.1

url:http://tomcat.apache.org/security-6.html

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-3375

Trust: 0.1

sources: CERT/CC: VU#903934 // VULMON: CVE-2011-4858 // PACKETSTORM: 121037 // PACKETSTORM: 108860 // PACKETSTORM: 110540 // PACKETSTORM: 112907 // PACKETSTORM: 109271 // PACKETSTORM: 111010 // PACKETSTORM: 110084 // PACKETSTORM: 112904 // PACKETSTORM: 109367 // PACKETSTORM: 111782 // PACKETSTORM: 112908 // JVNDB: JVNDB-2012-001003 // CNNVD: CNNVD-201201-056 // NVD: CVE-2011-4858

CREDITS

Red Hat

Trust: 0.8

sources: PACKETSTORM: 112907 // PACKETSTORM: 109271 // PACKETSTORM: 111010 // PACKETSTORM: 110084 // PACKETSTORM: 112904 // PACKETSTORM: 109367 // PACKETSTORM: 111782 // PACKETSTORM: 112908

SOURCES

db:CERT/CCid:VU#903934
db:VULMONid:CVE-2011-4858
db:PACKETSTORMid:121037
db:PACKETSTORMid:108860
db:PACKETSTORMid:110540
db:PACKETSTORMid:112907
db:PACKETSTORMid:109271
db:PACKETSTORMid:111010
db:PACKETSTORMid:110084
db:PACKETSTORMid:112904
db:PACKETSTORMid:109367
db:PACKETSTORMid:111782
db:PACKETSTORMid:112908
db:JVNDBid:JVNDB-2012-001003
db:CNNVDid:CNNVD-201201-056
db:NVDid:CVE-2011-4858

LAST UPDATE DATE

2025-06-26T22:15:52.140000+00:00


SOURCES UPDATE DATE

db:CERT/CCid:VU#903934date:2016-02-15T00:00:00
db:VULMONid:CVE-2011-4858date:2018-01-09T00:00:00
db:JVNDBid:JVNDB-2012-001003date:2013-03-08T00:00:00
db:CNNVDid:CNNVD-201201-056date:2012-01-09T00:00:00
db:NVDid:CVE-2011-4858date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:CERT/CCid:VU#903934date:2011-12-28T00:00:00
db:VULMONid:CVE-2011-4858date:2012-01-05T00:00:00
db:PACKETSTORMid:121037date:2013-04-01T15:55:00
db:PACKETSTORMid:108860date:2012-01-20T08:20:03
db:PACKETSTORMid:110540date:2012-03-07T23:23:06
db:PACKETSTORMid:112907date:2012-05-22T00:22:52
db:PACKETSTORMid:109271date:2012-02-01T02:54:44
db:PACKETSTORMid:111010date:2012-03-21T00:06:41
db:PACKETSTORMid:110084date:2012-02-23T04:44:48
db:PACKETSTORMid:112904date:2012-05-22T00:20:13
db:PACKETSTORMid:109367date:2012-02-03T00:18:35
db:PACKETSTORMid:111782date:2012-04-12T03:11:30
db:PACKETSTORMid:112908date:2012-05-22T00:23:56
db:JVNDBid:JVNDB-2012-001003date:2012-01-06T00:00:00
db:CNNVDid:CNNVD-201201-056date:2012-01-09T00:00:00
db:NVDid:CVE-2011-4858date:2012-01-05T19:55:01.033