SB2012111704 - Multiple vulnerabilities in Apache Tomcat 



SB2012111704 - Multiple vulnerabilities in Apache Tomcat

Published: November 17, 2012 Updated: June 15, 2023

Security Bulletin ID SB2012111704
Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Improper Authentication (CVE-ID: CVE-2012-5887)

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to HTTP Digest Access Authentication implementation in Apache Tomcat does not properly check for stale nonce values in conjunction with enforcement of proper credentials. A remote attacker can bypass intended access restrictions by sniffing the network for valid requests.


2) Improper Authentication (CVE-ID: CVE-2012-5886)

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to HTTP Digest Access Authentication implementation in Apache Tomcat. A remote attacker can bypass authentication via vectors related to the session ID.


Remediation

Install update from vendor's website.