CVE-2012-5886Medium· 5.0▾ SunlitThe HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches information about the authenticated user within the session state, which makes it easier for remot…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 1.8 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
8.8%
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches information about the authenticated user within the session state, which makes it easier for remote attackers to bypass authentication via vectors related to the session ID.
tomcat = 5.5.0tomcat = 5.5.1tomcat = 5.5.2tomcat = 5.5.3tomcat = 5.5.4tomcat = 5.5.5tomcat = 5.5.6tomcat = 5.5.7tomcat = 5.5.8tomcat = 5.5.9tomcat = 5.5.10tomcat = 5.5.11tomcat = 5.5.12tomcat = 5.5.13tomcat = 5.5.14tomcat = 5.5.15tomcat = 5.5.16tomcat = 5.5.17tomcat = 5.5.18tomcat = 5.5.19tomcat = 5.5.20tomcat = 5.5.21tomcat = 5.5.22tomcat = 5.5.23tomcat = 5.5.24tomcat = 5.5.25tomcat = 5.5.26tomcat = 5.5.27tomcat = 5.5.28tomcat = 5.5.29tomcat = 5.5.30tomcat = 5.5.31tomcat = 5.5.32tomcat = 5.5.33tomcat = 5.5.34tomcat = 5.5.35tomcat = 6.0tomcat = 6.0.0tomcat = 6.0.1tomcat = 6.0.2tomcat = 6.0.3tomcat = 6.0.4tomcat = 6.0.5tomcat = 6.0.6tomcat = 6.0.7tomcat = 6.0.8tomcat = 6.0.9tomcat = 6.0.10tomcat = 6.0.11tomcat = 6.0.12tomcat = 6.0.13tomcat = 6.0.14tomcat = 6.0.15tomcat = 6.0.16tomcat = 6.0.17tomcat = 6.0.18tomcat = 6.0.19tomcat = 6.0.20tomcat = 6.0.24tomcat = 6.0.26tomcat = 6.0.27tomcat = 6.0.28tomcat = 6.0.29tomcat = 6.0.30tomcat = 6.0.31tomcat = 6.0.32tomcat = 6.0.33tomcat = 6.0.35tomcat = 7.0.0tomcat = 7.0.1tomcat = 7.0.2tomcat = 7.0.3tomcat = 7.0.4tomcat = 7.0.5tomcat = 7.0.6tomcat = 7.0.7tomcat = 7.0.8tomcat = 7.0.9tomcat = 7.0.10tomcat = 7.0.11tomcat = 7.0.12tomcat = 7.0.13tomcat = 7.0.14tomcat = 7.0.15tomcat = 7.0.16tomcat = 7.0.17tomcat = 7.0.18tomcat = 7.0.19tomcat = 7.0.20tomcat = 7.0.21tomcat = 7.0.22tomcat = 7.0.23tomcat = 7.0.25tomcat = 7.0.28Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2013-2067Medium· 6.8java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements …
CVE-2012-5887Medium· 5.0The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values in conjunction with enforcement of proper credentials, whi…
CVE-2013-4590Medium· 4.3Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, o…
CVE-2013-4286Medium· 5.8Apache Tomcat before 6.0.39, 7.x before 7.0.47, and 8.x before 8.0.0-RC3, when an HTTP connector or AJP connector is used, does not properly handle certain inconsistent HTTP request headers, which allows remote attackers to trigger incor…
CVE-2013-4322Medium· 4.3Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 processes chunked transfer coding without properly handling (1) a large total amount of chunked data or (2) whitespace characters in an HTTP header value within a …
CVE-2012-3544Medium· 5.0Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attackers to cause a denial of service by streaming data.