← All CVEs

CVE-2012-5887

medium · 5

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values in conjunction with enforcement of proper credentials, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests.

5
CVSS
12.1%
EPSS (exploit prob.)
96th
EPSS percentile
2012-11-17
Published

AV:N/AC:L/Au:N/C:N/I:P/A:N

Weaknesses

CWE-287

Affected products

VendorProductAffected versions
apachetomcat>= 5.5.0, < 5.5.36
apachetomcat>= 6.0.0, < 6.0.36
apachetomcat>= 7.0.0, < 7.0.30

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2012-5887