#VU64540 Improper Authentication in Apache Tomcat - CVE-2012-5887 

 

#VU64540 Improper Authentication in Apache Tomcat - CVE-2012-5887

Published: June 21, 2022


Vulnerability identifier: #VU64540
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2012-5887
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Apache Tomcat
Software vendor:
Apache Foundation

Description

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to HTTP Digest Access Authentication implementation in Apache Tomcat does not properly check for stale nonce values in conjunction with enforcement of proper credentials. A remote attacker can bypass intended access restrictions by sniffing the network for valid requests.


Remediation

Install updates from vendor's website.

External links