Back

MEDIUM

Web: Bypass of security constraints

Published Dec 19, 2012

Description

org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when FORM authentication is used, allows remote attackers to bypass security-constraint checks by leveraging a previous setUserPrincipal call and then placing /j_security_check at the end of a URI.

Affected products

Remediation

Red Hat statement

Tomcat 5.5 has reached the end of its supported upstream life-cycle, and the Apache Tomcat project no longer tests security flaws to determine whether they affect Tomcat 5.5. Red Hat has tested tomcat 5.5 as shipped with Red Hat Enterprise Linux 5 and JBoss Enterprise Web Server 1, and found that it is affected by this flaw. Patches for tomcat 5.5 to address this flaw have been provided.

Metrics

References (50)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 19, 2012
Updated Aug 6, 2024
Reserved Jun 14, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Dec 4, 2012
GHSA-JGM2-M5CG-F66G