Back

LOW

tomcat: DIGEST authentication vulnerable to replay attacks

Published Jul 9, 2013

Description

The Tomcat 6 DIGEST authentication functionality as used in Red Hat Enterprise Linux 6 allows remote attackers to bypass intended access restrictions by performing a replay attack after a nonce becomes stale. NOTE: this issue is due to an incomplete fix for CVE-2012-5887.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 9, 2013
Updated Aug 6, 2024
Reserved Feb 19, 2013
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date May 28, 2013
ENISA EUVD
Assigner redhat
Published Jul 9, 2013
Updated Aug 6, 2024
Exploited since n/a
EUVD-2013-2033