Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2012-3546

Опубликовано: 19 дек. 2012
Источник: debian
EPSS Низкий

Описание

org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when FORM authentication is used, allows remote attackers to bypass security-constraint checks by leveraging a previous setUserPrincipal call and then placing /j_security_check at the end of a URI.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tomcat7fixed7.0.28-4package
tomcat6fixed6.0.35-6package
tomcat6fixed6.0.35-1+squeeze3squeezepackage

Примечания

  • DSA 2725

EPSS

Процентиль: 88%
0.04366
Низкий

Связанные уязвимости

ubuntu
больше 12 лет назад

org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when FORM authentication is used, allows remote attackers to bypass security-constraint checks by leveraging a previous setUserPrincipal call and then placing /j_security_check at the end of a URI.

redhat
больше 12 лет назад

org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when FORM authentication is used, allows remote attackers to bypass security-constraint checks by leveraging a previous setUserPrincipal call and then placing /j_security_check at the end of a URI.

nvd
больше 12 лет назад

org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when FORM authentication is used, allows remote attackers to bypass security-constraint checks by leveraging a previous setUserPrincipal call and then placing /j_security_check at the end of a URI.

github
около 3 лет назад

Authentication Bypass in Apache Tomcat

oracle-oval
больше 12 лет назад

ELSA-2013-0640: tomcat5 security update (IMPORTANT)

EPSS

Процентиль: 88%
0.04366
Низкий