HTTP: Apache Tomcat Form Authentication Information Disclosure

This signature detects attempts to exploit a known vulnerability against Apache Tomcat Form. A successful attack can result in the attacker gaining unauthorized information about the target system without the victim's knowledge.

Extended Description

Apache Tomcat is prone to a username-enumeration weakness because it displays different responses to login attempts, depending on whether or not the username exists. Attackers may exploit this weakness to discern valid usernames. This may aid them in brute-force password cracking or other attacks. The following are vulnerable: Tomcat 4.1.x (prior to 4.1.40) Tomcat 5.5x (prior to 5.5.28) Tomcat 6.0.x (prior to 6.0.20)

Affected Products

Debian linux

References

BugTraq: 35196

CVE: CVE-2009-0580

Short Name
HTTP:TOMCAT:FORM-AUTHENTICATION
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Apache Authentication CVE-2009-0580 Disclosure Form Information Tomcat bid:35196
Release Date
11/27/2012
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3494
False Positive
Unknown
Vendors

Apache_software_foundation

Red_hat

Suse

Ibm

Gentoo

Sun

Hp

Ubuntu

Mandriva

Debian

Vmware

Apple

CVSS Score

4.3

Found a potential security threat?