27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

CVE-2012-0022<br />

Apache Tomcat 7.0.x < 7.0.22 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 6333 FAMILY: Web Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:57082<br />

Description: Synopsis :\n\nThe remote web server is affected by multiple vulnerabilities.\n\nFor your<br />

information, the observed version of Apache Tomcat installed on the remote host is : \n %L<br />

\n\nVersions of Tomcat 7.0.x earlier than 7.0.22 are potentially affected by multiple<br />

vulnerabilities:\n\n - An information disclosure vulnerability exists. Request information is<br />

cached in two objects and these objects are not recycled at the same time. Further requests<br />

can obtain sensitive information if certain error conditions occur. (CVE-2011-3375)\n\n -<br />

The web server is not properly restricting access to the servlets that provide the<br />

functionality of the Manager application. This can allow untrusted web applications to<br />

access privileged internal functionality such as gathering information on running web<br />

applications and deploying additional web applications. (CVE-2011-3376)\nIAVB<br />

Reference : 2012-B-0035\nSTIG Finding Severity : Category I<br />

Solution: Upgrade to Apache Tomcat 7.0.22 or later.<br />

CVE-2011-3376<br />

Apache Tomcat 7.0.x < 7.0.23 Hash Collision Denial of Service<br />

<strong>PVS</strong> ID: 6334 FAMILY: Web Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:57541<br />

Description: Synopsis :\n\nThe remote web server is affected by a denial of service vulnerability.\n\nFor<br />

your information, the observed version of Apache Tomcat installed on the remote host is :<br />

\n %L \n\nVersions of Tomcat 7.0.x earlier than 7.0.23 are potentially affected by a denial<br />

of service vulnerability. Large numbers of crafted form parameters can cause excessive<br />

CPU consumption due to hash collisions.<br />

Solution: Upgrade to Apache Tomcat 7.0.23 or later.<br />

CVE-2012-0022<br />

IBM iSeries FTP Service Detection<br />

<strong>PVS</strong> ID: 6335 FAMILY: FTP Servers RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is running the IBM iSeries OS. The FTP service is running on this host.<br />

Solution: Solution Not Available<br />

CVE Not available<br />

PostgreSQL 8.3.x < 8.3.18 Multiple Vulnerabilities<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

<strong>PVS</strong> ID: 6336 FAMILY: Database NESSUS ID:Not Available<br />

Family Internet Services 1731

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!