CVE-2012-5886
Apache Tomcat < 5.5.36 - Authentication Bypass
Title source: ruleDescription
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches information about the authenticated user within the session state, which makes it easier for remote attackers to bypass authentication via vectors related to the session ID.
References (23)
... and 3 more
Scores
EPSS
0.0057
EPSS Percentile
68.3%
Classification
CWE
CWE-287
Status
draft
Affected Products (50)
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
... and 35 more
Timeline
Published
Nov 17, 2012
Tracked Since
Feb 18, 2026