Описание
org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when FORM authentication is used, allows remote attackers to bypass security-constraint checks by leveraging a previous setUserPrincipal call and then placing /j_security_check at the end of a URI.
Отчет
Tomcat 5.5 has reached the end of its supported upstream life-cycle, and the Apache Tomcat project no longer tests security flaws to determine whether they affect Tomcat 5.5. Red Hat has tested tomcat 5.5 as shipped with Red Hat Enterprise Linux 5 and JBoss Enterprise Web Server 1, and found that it is affected by this flaw. Patches for tomcat 5.5 to address this flaw have been provided.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat JBoss BRMS 5 | jbossweb | Affected | ||
| Red Hat JBoss Data Grid 6 | jbossweb | Not affected | ||
| Red Hat JBoss Enterprise Web Server 2 | tomcat7 | Not affected | ||
| Red Hat JBoss Operations Network 3 | jbossweb | Not affected | ||
| Red Hat JBoss Portal 4 | jbossweb | Affected | ||
| Red Hat JBoss Portal 5 | jbossweb | Affected | ||
| Red Hat JBoss SOA Platform 4 | jbossweb | Affected | ||
| Red Hat JBoss SOA Platform 5 | jbossweb | Affected | ||
| JBEWP 5 for RHEL 5 | aopalliance | Fixed | RHSA-2013:0196 | 24.01.2013 |
| JBEWP 5 for RHEL 5 | apache-cxf | Fixed | RHSA-2013:0196 | 24.01.2013 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS2
Связанные уязвимости
org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when FORM authentication is used, allows remote attackers to bypass security-constraint checks by leveraging a previous setUserPrincipal call and then placing /j_security_check at the end of a URI.
org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when FORM authentication is used, allows remote attackers to bypass security-constraint checks by leveraging a previous setUserPrincipal call and then placing /j_security_check at the end of a URI.
org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6 ...
EPSS
5.5 Medium
CVSS2