Information disclosure in httpclient - CVE-2011-1498
Published: July 8, 2011 / Updated: August 11, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows remote web servers to obtain sensitive information by logging this header.
Affected software
IBM Engineering Systems Design Rhapsody
IBM Tivoli Monitoring
IBM Cloud Application Performance Management (APM)
IBM Tivoli Application Dependency Discovery Manager
Cloud Pak for Security (CP4S)
IBM Rational Asset Manager
How to mitigate CVE-2011-1498
IBM Rational Asset Manager - update to 7.5.4.15
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.16
IBM Engineering Systems Design Rhapsody - addressed in versions 9.0.1.0.6, 9.0.2.0.2
External References
- http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061440.html
- http://marc.info/?l=httpclient-users&m=129853896315461&w=2
- http://marc.info/?l=httpclient-users&m=129856318011586&w=2
- http://marc.info/?l=httpclient-users&m=129857589129183&w=2
- http://marc.info/?l=httpclient-users&m=129858274406594&w=2
- http://marc.info/?l=httpclient-users&m=129858299106950&w=2
- http://openwall.com/lists/oss-security/2011/04/07/7
- http://openwall.com/lists/oss-security/2011/04/08/1
- http://securityreason.com/securityalert/8298
- http://www.apache.org/dist/httpcomponents/httpclient/RELEASE_NOTES-4.1.x.txt
- http://www.kb.cert.org/vuls/id/153049
- http://www.securityfocus.com/bid/46974
- https://bugzilla.redhat.com/show_bug.cgi?id=709531
- https://issues.apache.org/jira/browse/HTTPCLIENT-1061
Related Security Bulletins
- Information disclosure in nahi httpclient
- Multiple vulnerabilities in IBM Tivoli Monitoring
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in IBM Tivoli Application Dependency Discovery Manager
- Multiple vulnerabilities in IBM Engineering Systems Design Rhapsody
- Multiple vulnerabilities in IBM Application Performance Management
- Multiple vulnerabilities in IBM Rational Asset Manager