Executive Summary

Informations
Name CVE-2013-2071 First vendor Publication 2013-06-01
Vendor Cve Last vendor Modification 2017-05-23

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:H/Au:N/C:P/I:N/A:N)
Cvss Base Score 2.6 Attack Range Network
Cvss Impact Score 2.9 Attack Complexity High
Cvss Expoit Score 4.9 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request information intended for other applications in opportunistic circumstances via an application that records the requests that it processes.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2071

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-200 Information Exposure

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:18192
 
Oval ID: oval:org.mitre.oval:def:18192
Title: USN-1841-1 -- tomcat6, tomcat7 vulnerabilities
Description: Several security issues were fixed in Tomcat.
Family: unix Class: patch
Reference(s): USN-1841-1
CVE-2012-3544
CVE-2013-2067
CVE-2013-2071
Version: 7
Platform(s): Ubuntu 13.04
Ubuntu 12.10
Ubuntu 12.04
Ubuntu 10.04
Product(s): tomcat7
tomcat6
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:26527
 
Oval ID: oval:org.mitre.oval:def:26527
Title: Allows context-dependent attackers to obtain sensitive request information
Description: java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request information intended for other applications in opportunistic circumstances via an application that records the requests that it processes.
Family: windows Class: vulnerability
Reference(s): CVE-2013-2071
Version: 3
Platform(s): Microsoft Windows 2000
Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Vista
Microsoft Windows XP
Product(s): Apache Tomcat
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 31

Information Assurance Vulnerability Management (IAVM)

Date Description
2013-05-16 IAVM : 2013-B-0047 - Multiple Vulnerabilities in Apache Tomcat
Severity : Category I - VMSKEY : V0037947

Nessus® Vulnerability Scanner

Date Description
2014-12-15 Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-201412-29.nasl - Type : ACT_GATHER_INFO
2014-06-26 Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2013-1011.nasl - Type : ACT_GATHER_INFO
2014-06-26 Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2013-1012.nasl - Type : ACT_GATHER_INFO
2014-06-13 Name : The remote openSUSE host is missing a security update.
File : openSUSE-2013-632.nasl - Type : ACT_GATHER_INFO
2014-04-09 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-2897.nasl - Type : ACT_GATHER_INFO
2014-02-05 Name : The remote host has a version of Oracle Secure Global Desktop that is affecte...
File : oracle_secure_global_desktop_jan_2014_cpu.nasl - Type : ACT_GATHER_INFO
2013-09-04 Name : The remote Amazon Linux AMI host is missing a security update.
File : ala_ALAS-2013-191.nasl - Type : ACT_GATHER_INFO
2013-05-29 Name : The remote Ubuntu host is missing one or more security-related patches.
File : ubuntu_USN-1841-1.nasl - Type : ACT_GATHER_INFO
2013-05-26 Name : The remote Fedora host is missing a security update.
File : fedora_2013-7979.nasl - Type : ACT_GATHER_INFO
2013-05-22 Name : The remote Fedora host is missing a security update.
File : fedora_2013-7993.nasl - Type : ACT_GATHER_INFO
2013-05-22 Name : The remote Fedora host is missing a security update.
File : fedora_2013-7999.nasl - Type : ACT_GATHER_INFO
2013-05-15 Name : The remote Apache Tomcat server is affected by multiple vulnerabilities.
File : tomcat_7_0_40.nasl - Type : ACT_GATHER_INFO

Sources (Detail)

Source Url
BID http://www.securityfocus.com/bid/59798
http://www.securityfocus.com/bid/64758
BUGTRAQ http://archives.neohapsis.com/archives/bugtraq/2013-05/0040.html
CONFIRM http://svn.apache.org/viewvc?view=revision&revision=1471372
http://svn.apache.org/viewvc/tomcat/tc7.0.x/trunk/java/org/apache/catalina/co...
http://tomcat.apache.org/security-7.html
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
https://issues.apache.org/bugzilla/show_bug.cgi?id=54178
FEDORA http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105855.html
http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105886.html
http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106342.html
HP http://marc.info/?l=bugtraq&m=139344248911289&w=2
SUSE http://lists.opensuse.org/opensuse-updates/2013-08/msg00013.html
UBUNTU http://www.ubuntu.com/usn/USN-1841-1

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
Date Informations
2021-05-04 12:24:52
  • Multiple Updates
2021-04-22 01:29:48
  • Multiple Updates
2020-05-23 00:36:51
  • Multiple Updates
2017-05-23 09:22:43
  • Multiple Updates
2014-12-16 13:25:01
  • Multiple Updates
2014-06-27 13:26:13
  • Multiple Updates
2014-06-14 13:35:21
  • Multiple Updates
2014-04-10 13:23:11
  • Multiple Updates
2014-03-06 13:22:14
  • Multiple Updates
2014-02-17 11:18:56
  • Multiple Updates
2014-01-17 13:19:33
  • Multiple Updates
2013-11-25 13:20:50
  • Multiple Updates
2013-11-11 12:40:23
  • Multiple Updates
2013-08-22 17:19:58
  • Multiple Updates
2013-06-15 13:18:42
  • Multiple Updates
2013-06-03 21:28:51
  • Multiple Updates
2013-06-01 17:19:13
  • First insertion