CVE-2009-0580
Exposure of Sensitive Information in Apache Tomcat
EPSS 94.4%
描述
Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, allows remote attackers to enumerate valid usernames via requests to /j_security_check with malformed URL encoding of passwords, related to improper error checking in the (1) MemoryRealm, (2) DataSourceRealm, and (3) JDBCRealm authentication realms, as demonstrated by a % (percent) value for the j_password parameter.
如何修補 CVE-2009-0580
要修補 CVE-2009-0580,請將受影響套件升級到下列已修補版本。
- Maven/org.apache.tomcat:tomcat—升級至 4.1.40 或更新版本
CVE-2009-0580 正在被利用嗎?
可能 — EPSS 為 94.4%,屬於高被利用機率區間,建議優先修補。
受影響套件(1)
- >= 4.1.0, < 4.1.40