TROYANOSYVIRUS
Voltar para CVEs

CVE-2012-5887

N/A

Descricao

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values in conjunction with enforcement of proper credentials, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests.

Detalhes CVE

Pontuacao CVSS v3.1N/A
Publicado11/17/2012
Ultima modificacao10/30/2025
Fontenvd
Avistamentos honeypot0

Produtos afetados

apache:tomcat

Fraquezas (CWE)

CWE-287

Referencias

http://rhn.redhat.com/errata/RHSA-2013-0623.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2013-0629.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2013-0631.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2013-0632.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2013-0633.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2013-0640.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2013-0647.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2013-0648.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2013-0726.html(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/51371(af854a3a-2127-422b-91ae-364da2661108)
http://tomcat.apache.org/security-5.html(af854a3a-2127-422b-91ae-364da2661108)
http://tomcat.apache.org/security-6.html(af854a3a-2127-422b-91ae-364da2661108)
http://tomcat.apache.org/security-7.html(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21626891(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/56403(af854a3a-2127-422b-91ae-364da2661108)
http://www.ubuntu.com/usn/USN-1637-1(af854a3a-2127-422b-91ae-364da2661108)

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.