PT-2012-4799 · Apache+4 · Apache Tomcat+4

Published

2012-10-19

·

Updated

2022-05-17

·

CVE-2012-3546

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 6.x before 6.0.36 Apache Tomcat versions 7.x before 7.0.30
Description The issue allows remote attackers to bypass security-constraint checks when FORM authentication is used. This can be achieved by leveraging a previous setUserPrincipal call and then placing /j security check at the end of a URI. The vulnerability can be exploited if some other component, such as the Single-Sign-On valve, had called request.setUserPrincipal() before the call to FormAuthenticator#authenticate().
Recommendations For Apache Tomcat 6.x before 6.0.36, update to version 6.0.36 or later to resolve the issue. For Apache Tomcat 7.x before 7.0.30, update to version 7.0.30 or later to resolve the issue. As a temporary workaround, consider restricting access to the /j security check endpoint until a patch is available.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2013_0623
CVE-2012-3546
GHSA-JGM2-M5CG-F66G
HPSBUX02866
RHSA-2013:0005
RHSA-2013:0147
RHSA-2013:0158
RHSA-2013:0164
RHSA-2013:0191
RHSA-2013:0192
RHSA-2013:0193
RHSA-2013:0195
RHSA-2013:0196
RHSA-2013:0197
RHSA-2013:0623
RHSA-2013:0640
RHSA-2013:0641
RHSA-2013_0623
RHSA-2013_0640

Affected Products

Apache Tomcat
Centos
Hp-Ux
Red Hat
Suse