Apache Tomcat Permissions Privileges and Access Controls Vulnerability - CVE-2012-5885 - Vulnerability Database

Apache Tomcat Permissions Privileges and Access Controls Vulnerability - CVE-2012-5885

Medium
Reference: CVE-2012-5885
Title: Apache Tomcat Permissions Privileges and Access Controls Vulnerability
Overview:

The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36 6.x before 6.0.36 and 7.x before 7.0.30 tracks cnonce (aka client nonce) values instead of nonce (aka server nonce) and nc (aka nonce-count) values which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests a different vulnerability than CVE-2011-1184.