CVE-2011-5063

Apache Tomcat < 5.5.34 - Authentication Bypass

Title source: rule

Description

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check realm values, which might allow remote attackers to bypass intended access restrictions by leveraging the availability of a protection space with weaker authentication or authorization requirements, a different vulnerability than CVE-2011-1184.

References (22)

... and 2 more

Scores

EPSS 0.0196
EPSS Percentile 83.3%

Classification

CWE
CWE-287
Status draft

Affected Products (50)

apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
... and 35 more

Timeline

Published Jan 14, 2012
Tracked Since Feb 18, 2026