Описание
org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when FORM authentication is used, allows remote attackers to bypass security-constraint checks by leveraging a previous setUserPrincipal call and then placing /j_security_check at the end of a URI.
Отчет
Tomcat 5.5 has reached the end of its supported upstream life-cycle, and the Apache Tomcat project no longer tests security flaws to determine whether they affect Tomcat 5.5. Red Hat has tested tomcat 5.5 as shipped with Red Hat Enterprise Linux 5 and JBoss Enterprise Web Server 1, and found that it is affected by this flaw. Patches for tomcat 5.5 to address this flaw have been provided.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat JBoss BRMS 5 | jbossweb | Affected | ||
Red Hat JBoss Data Grid 6 | jbossweb | Not affected | ||
Red Hat JBoss Enterprise Web Server 1 | eap4.3 | Affected | ||
Red Hat JBoss Enterprise Web Server 1 | eap5 | Affected | ||
Red Hat JBoss Enterprise Web Server 1 | eap6 | Affected | ||
Red Hat JBoss Enterprise Web Server 1 | ewp5 | Affected | ||
Red Hat JBoss Enterprise Web Server 2 | tomcat7 | Not affected | ||
Red Hat JBoss Operations Network 3.1 | jbossweb | Not affected | ||
Red Hat JBoss Portal 4 | jbossweb | Affected | ||
Red Hat JBoss Portal 5 | jbossweb | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS2
Связанные уязвимости
org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when FORM authentication is used, allows remote attackers to bypass security-constraint checks by leveraging a previous setUserPrincipal call and then placing /j_security_check at the end of a URI.
org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when FORM authentication is used, allows remote attackers to bypass security-constraint checks by leveraging a previous setUserPrincipal call and then placing /j_security_check at the end of a URI.
org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6 ...
EPSS
5.5 Medium
CVSS2