---
id: CVE-2012-5887
title: >-
  The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x
  before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly
  check for stale nonce values in conjunction with enforcement of proper
  credentials, whi…
summary: >-
  The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x
  before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly
  check for stale nonce values in conjunction with enforcement of proper
  credentials, whi…
severity: medium
cvss: 5
cvssVector: 'AV:N/AC:L/Au:N/C:N/I:P/A:N'
cwe:
  - CWE-287
vendor: apache
product: tomcat
affected:
  - 'tomcat >= 5.5.0, < 5.5.36'
  - 'tomcat >= 6.0.0, < 6.0.36'
  - 'tomcat >= 7.0.0, < 7.0.30'
patched:
  - tomcat 7.0.30
published: '2012-11-17'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T20:17:05.797'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2012-5887'
references:
  - url: 'http://lists.opensuse.org/opensuse-updates/2012-12/msg00089.html'
    label: cve@mitre.org
  - url: 'http://lists.opensuse.org/opensuse-updates/2012-12/msg00090.html'
    label: cve@mitre.org
  - url: 'http://lists.opensuse.org/opensuse-updates/2013-01/msg00037.html'
    label: cve@mitre.org
  - url: 'http://rhn.redhat.com/errata/RHSA-2013-0623.html'
    label: cve@mitre.org
  - url: 'http://rhn.redhat.com/errata/RHSA-2013-0629.html'
    label: cve@mitre.org
  - url: 'http://rhn.redhat.com/errata/RHSA-2013-0631.html'
    label: cve@mitre.org
  - url: 'http://rhn.redhat.com/errata/RHSA-2013-0632.html'
    label: cve@mitre.org
  - url: 'http://rhn.redhat.com/errata/RHSA-2013-0633.html'
    label: cve@mitre.org
  - url: 'http://rhn.redhat.com/errata/RHSA-2013-0640.html'
    label: cve@mitre.org
  - url: 'http://rhn.redhat.com/errata/RHSA-2013-0647.html'
    label: cve@mitre.org
  - url: 'http://rhn.redhat.com/errata/RHSA-2013-0648.html'
    label: cve@mitre.org
  - url: 'http://rhn.redhat.com/errata/RHSA-2013-0726.html'
    label: cve@mitre.org
  - url: 'http://secunia.com/advisories/51371'
    label: cve@mitre.org
  - url: 'http://svn.apache.org/viewvc?view=revision&revision=1377807'
    label: cve@mitre.org
  - url: 'http://svn.apache.org/viewvc?view=revision&revision=1380829'
    label: cve@mitre.org
  - url: 'http://svn.apache.org/viewvc?view=revision&revision=1392248'
    label: cve@mitre.org
  - url: 'http://tomcat.apache.org/security-5.html'
    label: cve@mitre.org
  - url: 'http://tomcat.apache.org/security-6.html'
    label: cve@mitre.org
  - url: 'http://tomcat.apache.org/security-7.html'
    label: cve@mitre.org
  - url: 'http://www-01.ibm.com/support/docview.wss?uid=swg21626891'
    label: cve@mitre.org
  - url: 'http://www.securityfocus.com/bid/56403'
    label: cve@mitre.org
  - url: 'http://www.ubuntu.com/usn/USN-1637-1'
    label: cve@mitre.org
  - url: 'https://exchange.xforce.ibmcloud.com/vulnerabilities/79809'
    label: cve@mitre.org
  - url: 'http://lists.opensuse.org/opensuse-updates/2012-12/msg00089.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-updates/2012-12/msg00090.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-updates/2013-01/msg00037.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2013-0623.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2013-0629.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2013-0631.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2013-0632.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2013-0633.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2013-0640.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2013-0647.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2013-0648.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2013-0726.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://secunia.com/advisories/51371'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://svn.apache.org/viewvc?view=revision&revision=1377807'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://svn.apache.org/viewvc?view=revision&revision=1380829'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://svn.apache.org/viewvc?view=revision&revision=1392248'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://tomcat.apache.org/security-5.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://tomcat.apache.org/security-6.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://tomcat.apache.org/security-7.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www-01.ibm.com/support/docview.wss?uid=swg21626891'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securityfocus.com/bid/56403'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.ubuntu.com/usn/USN-1637-1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://exchange.xforce.ibmcloud.com/vulnerabilities/79809'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.12098
epssPercentile: 0.96057
ingestedAt: '2026-10-09T21:12:42.310Z'
---

## Overview

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values in conjunction with enforcement of proper credentials, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests.

## Affected

- `tomcat >= 5.5.0, < 5.5.36`
- `tomcat >= 6.0.0, < 6.0.36`
- `tomcat >= 7.0.0, < 7.0.30`

## Remediation

Upgrade past the affected range:

- `tomcat 7.0.30`
