The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.17 uses certain insecure ciphers, including the anonymous cipher, which allows remote attackers to obtain sensitive information or have other, unspecified impacts.
CVSS Details
- CVSS 3.1 Base Score: 3.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Tomcat | — | Upgrade Apache Tomcat to the latest available versionUpgrade Apache Tomcat to 4.1.32Upgrade Apache Tomcat to 5.0.0Upgrade Apache Tomcat to 5.5.17 | May 17, 2012 | May 9, 2007 |
| Suse | — | Upgrade tomcat55-jsp-2_0-api-javadocUpgrade jakarta-tomcat-docUpgrade tomcat55-webappsUpgrade tomcat55-servlet-2_4-apiUpgrade tomcat5Upgrade tomcat55Upgrade tomcat55-servlet-2_4-api-javadocUpgrade tomcat55-common-libUpgrade tomcat55-admin-webappsUpgrade tomcat55-jsp-2_0-apiUpgrade tomcat5-webappsUpgrade jakarta-tomcatUpgrade apache2-jakarta-tomcat-connectorsUpgrade tomcat55-jasperUpgrade jakarta-tomcat-examplesUpgrade tomcat55-jasper-javadocUpgrade tomcat5-admin-webappsUpgrade tomcat55-server-libUpgrade suse-releaseUpgrade apache-jakarta-tomcat-connectorsUpgrade apache2-mod_jk | Feb 17, 2015 | May 9, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub