The vendor explicitly identifies these products as affected by this CVE.
- tomcat6 as a component of Red Hat Enterprise Linux 6
- tomcat6-admin-webapps as a component of Red Hat Enterprise Linux 6
- tomcat6-docs-webapp as a component of Red Hat Enterprise Linux 6
- tomcat6-el-2.1-api as a component of Red Hat Enterprise Linux 6
- tomcat6-javadoc as a component of Red Hat Enterprise Linux 6
- tomcat6-jsp-2.1-api as a component of Red Hat Enterprise Linux 6
- tomcat6-lib as a component of Red Hat Enterprise Linux 6
- tomcat6-log4j as a component of Red Hat Enterprise Linux 6
- tomcat6-servlet-2.5-api as a component of Red Hat Enterprise Linux 6
- tomcat6-webapps as a component of Red Hat Enterprise Linux 6
- tomcat6.src as a component of Red Hat Enterprise Linux 6
- tomcat as a component of Red Hat Enterprise Linux 8
- Summary
- A flaw was found in Apache Tomcat. When DIGEST authentication was configured, any user not known to the configured Realm would be authenticated if they presented the password "null". This allows a remote attacker to bypass security controls.
- Remediation
- Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
