CVE-2012-3546: Medium severity tomcat vulnerability
org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when FORM authentication is used, allows remote attackers to bypass security-constraint checks by leveraging a previous setUserPrincipal call and then placing /jsecuritycheck at the end of a URI.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3546?
CVE-2012-3546 has been classified as a medium severity vulnerability that allows attackers to bypass security constraints.
How do I fix CVE-2012-3546?
To mitigate CVE-2012-3546, upgrade to Apache Tomcat versions 6.0.36 or 7.0.30 or later.
What versions of Apache Tomcat are affected by CVE-2012-3546?
CVE-2012-3546 affects Apache Tomcat versions 6.x before 6.0.36 and 7.x before 7.0.30.
What type of vulnerability is CVE-2012-3546?
CVE-2012-3546 is a security vulnerability that can allow unauthorized access through FORM authentication.
Can CVE-2012-3546 affect web applications?
Yes, CVE-2012-3546 can impact web applications that rely on Apache Tomcat for handling FORM authentication.