CVE-2012-5885
⚪ Do wiadomości
Błąd w uwierzytelnianiu HTTP Digest w Apache Tomcat umożliwia obejście ograniczeń dostępu.
CVSS
5.0
EPSS
9.0%
Exploit
none
Vendor
apache
Opis źródłowy (NVD)
The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 tracks cnonce (aka client nonce) values instead of nonce (aka server nonce) and nc (aka nonce-count) values, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, a different vulnerability than CVE-2011-1184.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.0 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 9.0% |
| Opublikowano (NVD) | 2012-11-17 19:55:02 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-09 20:17:05 UTC |
Referencje
- http://lists.opensuse.org/opensuse-updates/2012-12/msg00089.html ([email protected])
- http://lists.opensuse.org/opensuse-updates/2012-12/msg00090.html ([email protected])
- http://lists.opensuse.org/opensuse-updates/2013-01/msg00037.html ([email protected])
- http://marc.info/?l=bugtraq&m=136485229118404&w=2 ([email protected])
- http://marc.info/?l=bugtraq&m=136612293908376&w=2 ([email protected])
- http://rhn.redhat.com/errata/RHSA-2013-0623.html ([email protected])
- http://rhn.redhat.com/errata/RHSA-2013-0629.html ([email protected])
- http://rhn.redhat.com/errata/RHSA-2013-0631.html ([email protected])
- http://rhn.redhat.com/errata/RHSA-2013-0632.html ([email protected])
- http://rhn.redhat.com/errata/RHSA-2013-0633.html ([email protected])
- http://rhn.redhat.com/errata/RHSA-2013-0640.html ([email protected])
- http://rhn.redhat.com/errata/RHSA-2013-0647.html ([email protected])
- http://rhn.redhat.com/errata/RHSA-2013-0648.html ([email protected])
- http://rhn.redhat.com/errata/RHSA-2013-0726.html ([email protected])
- http://secunia.com/advisories/51371 ([email protected])
- http://svn.apache.org/viewvc?view=revision&revision=1377807 ([email protected])
- http://svn.apache.org/viewvc?view=revision&revision=1380829 ([email protected])
- http://svn.apache.org/viewvc?view=revision&revision=1392248 ([email protected])
- http://tomcat.apache.org/security-5.html ([email protected])
- http://tomcat.apache.org/security-6.html ([email protected]) [Vendor Advisory]
- http://tomcat.apache.org/security-7.html ([email protected]) [Vendor Advisory]
- http://www-01.ibm.com/support/docview.wss?uid=swg21626891 ([email protected])
- http://www.securityfocus.com/bid/56403 ([email protected])
- http://www.ubuntu.com/usn/USN-1637-1 ([email protected])
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80408 ([email protected])
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19432 ([email protected])