The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 tracks cnonce (aka client nonce) values instead of nonce (aka server nonce) and nc (aka nonce-count) values, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, a different vulnerability than CVE-2011-1184.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2012-11-17T19:00:00
Updated: 2024-08-06T21:21:27.917Z
Reserved: 2012-11-17T00:00:00
Link: CVE-2012-5885
Vulnrichment
No data.
NVD
Status : Modified
Published: 2012-11-17T19:55:02.673
Modified: 2024-11-21T01:45:26.140
Link: CVE-2012-5885
Redhat