Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2012-5885
Description:The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 tracks cnonce (aka client nonce) values instead of nonce (aka server nonce) and nc (aka nonce- count) values, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, a different vulnerability than CVE-2011-1184.
Test IDs: 1.3.6.1.4.1.25623.1.1.4.2013.0226.1   1.3.6.1.4.1.25623.1.0.123666  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2012-5885
BugTraq ID: 56403
http://www.securityfocus.com/bid/56403
HPdes Security Advisory: HPSBUX02860
http://marc.info/?l=bugtraq&m=136485229118404&w=2
HPdes Security Advisory: HPSBUX02866
http://marc.info/?l=bugtraq&m=136612293908376&w=2
HPdes Security Advisory: SSRT101139
http://marc.info/?l=bugtraq&m=136612293908376&w=2
HPdes Security Advisory: SSRT101146
http://marc.info/?l=bugtraq&m=136485229118404&w=2
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19432
RedHat Security Advisories: RHSA-2013:0623
http://rhn.redhat.com/errata/RHSA-2013-0623.html
RedHat Security Advisories: RHSA-2013:0629
http://rhn.redhat.com/errata/RHSA-2013-0629.html
RedHat Security Advisories: RHSA-2013:0631
http://rhn.redhat.com/errata/RHSA-2013-0631.html
RedHat Security Advisories: RHSA-2013:0632
http://rhn.redhat.com/errata/RHSA-2013-0632.html
RedHat Security Advisories: RHSA-2013:0633
http://rhn.redhat.com/errata/RHSA-2013-0633.html
RedHat Security Advisories: RHSA-2013:0640
http://rhn.redhat.com/errata/RHSA-2013-0640.html
RedHat Security Advisories: RHSA-2013:0647
http://rhn.redhat.com/errata/RHSA-2013-0647.html
RedHat Security Advisories: RHSA-2013:0648
http://rhn.redhat.com/errata/RHSA-2013-0648.html
RedHat Security Advisories: RHSA-2013:0726
http://rhn.redhat.com/errata/RHSA-2013-0726.html
http://secunia.com/advisories/51371
SuSE Security Announcement: openSUSE-SU-2012:1700 (Google Search)
http://lists.opensuse.org/opensuse-updates/2012-12/msg00089.html
SuSE Security Announcement: openSUSE-SU-2012:1701 (Google Search)
http://lists.opensuse.org/opensuse-updates/2012-12/msg00090.html
SuSE Security Announcement: openSUSE-SU-2013:0147 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-01/msg00037.html
http://www.ubuntu.com/usn/USN-1637-1
XForce ISS Database: tomcat-replay-security-bypass(80408)
https://exchange.xforce.ibmcloud.com/vulnerabilities/80408




© 1998-2025 E-Soft Inc. All rights reserved.