vendor:
Tomcat
by:
SecurityFocus
7.5
CVSS
HIGH
Username Enumeration Weakness
200
CWE
Product Name: Tomcat
Affected Version From: Tomcat 4.1.x (prior to 4.1.40), Tomcat 5.5x (prior to 5.5.28), Tomcat 6.0.x (prior to 6.0.20)
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Apache Tomcat Username Enumeration Weakness
Apache Tomcat is prone to a username-enumeration weakness because it displays different responses to login attempts, depending on whether or not the username exists. Attackers may exploit this weakness to discern valid usernames. This may aid them in brute-force password cracking or other attacks.
Mitigation:
Upgrade to Apache Tomcat 4.1.40, 5.5.28, or 6.0.20 or later.