CVE-2012-5887: Medium severity tomcat vulnerability
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values in conjunction with enforcement of proper credentials, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5887?
CVE-2012-5887 is considered a medium severity vulnerability as it allows attackers to bypass authentication controls.
How do I fix CVE-2012-5887?
To fix CVE-2012-5887, upgrade Apache Tomcat to version 5.5.36, 6.0.36, or 7.0.30 or later.
What versions of Apache Tomcat are affected by CVE-2012-5887?
CVE-2012-5887 affects Apache Tomcat versions 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30.
Can attackers exploit CVE-2012-5887 remotely?
Yes, attackers can exploit CVE-2012-5887 remotely by manipulating HTTP Digest Access Authentication.
Is there a workaround for CVE-2012-5887?
The best workaround for CVE-2012-5887 is to upgrade to a fixed version, as no other specific mitigations are provided.