CyberRota Analysis
This is a low severity vulnerability with a CVSS score of 1.9. It affects Apache.
CVE
CVE-2011-2204
Severity
LOW
CVSS
1.9
EPSS
0.67%
Apache
Original NVD Description
Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.17, when the MemoryUserDatabase is used, creates log entries containing passwords upon encountering errors in JMX user creation, which allows local users to obtain sensitive information by reading a log file.