Back

MEDIUM

tomcat: three DIGEST authentication implementation issues

Published Nov 17, 2012

Description

The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 tracks cnonce (aka client nonce) values instead of nonce (aka server nonce) and nc (aka nonce-count) values, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, a different vulnerability than CVE-2011-1184.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (31)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 17, 2012
Updated Aug 6, 2024
Reserved Nov 17, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Nov 5, 2012
GHSA-99RF-92V6-CWX4