CVE-2012-5885Medium· 5.0▾ SunlitThe replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 tracks cnonce (aka client nonce) values instead of nonce (aka …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 1.8 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
9.0%
The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 tracks cnonce (aka client nonce) values instead of nonce (aka server nonce) and nc (aka nonce-count) values, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, a different vulnerability than CVE-2011-1184.
tomcat = 5.5.0tomcat = 5.5.1tomcat = 5.5.2tomcat = 5.5.3tomcat = 5.5.4tomcat = 5.5.5tomcat = 5.5.6tomcat = 5.5.7tomcat = 5.5.8tomcat = 5.5.9tomcat = 5.5.10tomcat = 5.5.11tomcat = 5.5.12tomcat = 5.5.13tomcat = 5.5.14tomcat = 5.5.15tomcat = 5.5.16tomcat = 5.5.17tomcat = 5.5.18tomcat = 5.5.19tomcat = 5.5.20tomcat = 5.5.21tomcat = 5.5.22tomcat = 5.5.23tomcat = 5.5.24tomcat = 5.5.25tomcat = 5.5.26tomcat = 5.5.27tomcat = 5.5.28tomcat = 5.5.29tomcat = 5.5.30tomcat = 5.5.31tomcat = 5.5.32tomcat = 5.5.33tomcat = 5.5.34tomcat = 5.5.35tomcat = 6.0tomcat = 6.0.0tomcat = 6.0.1tomcat = 6.0.2tomcat = 6.0.3tomcat = 6.0.4tomcat = 6.0.5tomcat = 6.0.6tomcat = 6.0.7tomcat = 6.0.8tomcat = 6.0.9tomcat = 6.0.10tomcat = 6.0.11tomcat = 6.0.12tomcat = 6.0.13tomcat = 6.0.14tomcat = 6.0.15tomcat = 6.0.16tomcat = 6.0.17tomcat = 6.0.18tomcat = 6.0.19tomcat = 6.0.20tomcat = 6.0.24tomcat = 6.0.26tomcat = 6.0.27tomcat = 6.0.28tomcat = 6.0.29tomcat = 6.0.30tomcat = 6.0.31tomcat = 6.0.32tomcat = 6.0.33tomcat = 6.0.35tomcat = 7.0.0tomcat = 7.0.1tomcat = 7.0.2tomcat = 7.0.3tomcat = 7.0.4tomcat = 7.0.5tomcat = 7.0.6tomcat = 7.0.7tomcat = 7.0.8tomcat = 7.0.9tomcat = 7.0.10tomcat = 7.0.11tomcat = 7.0.12tomcat = 7.0.13tomcat = 7.0.14tomcat = 7.0.15tomcat = 7.0.16tomcat = 7.0.17tomcat = 7.0.18tomcat = 7.0.19tomcat = 7.0.20tomcat = 7.0.21tomcat = 7.0.22tomcat = 7.0.23tomcat = 7.0.25tomcat = 7.0.28Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2012-4431Medium· 4.3org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism via a request that lacks a sessio…
CVE-2013-4590Medium· 4.3Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, o…
CVE-2013-4286Medium· 5.8Apache Tomcat before 6.0.39, 7.x before 7.0.47, and 8.x before 8.0.0-RC3, when an HTTP connector or AJP connector is used, does not properly handle certain inconsistent HTTP request headers, which allows remote attackers to trigger incor…
CVE-2013-4322Medium· 4.3Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 processes chunked transfer coding without properly handling (1) a large total amount of chunked data or (2) whitespace characters in an HTTP header value within a …
CVE-2012-3544Medium· 5.0Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attackers to cause a denial of service by streaming data.
CVE-2013-2067Medium· 6.8java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements …