CVE-2012-5886
Summary
| CVE | CVE-2012-5886 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-11-17 19:55:02 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches information about the authenticated user within the session state, which makes it easier for remote attackers to bypass authentication via vectors related to the session ID. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Tomcat | 5.5.0 | All | All | All |
| Application | Apache | Tomcat | 5.5.1 | All | All | All |
| Application | Apache | Tomcat | 5.5.10 | All | All | All |
| Application | Apache | Tomcat | 5.5.11 | All | All | All |
| Application | Apache | Tomcat | 5.5.12 | All | All | All |
| Application | Apache | Tomcat | 5.5.13 | All | All | All |
| Application | Apache | Tomcat | 5.5.14 | All | All | All |
| Application | Apache | Tomcat | 5.5.15 | All | All | All |
| Application | Apache | Tomcat | 5.5.16 | All | All | All |
| Application | Apache | Tomcat | 5.5.17 | All | All | All |
| Application | Apache | Tomcat | 5.5.18 | All | All | All |
| Application | Apache | Tomcat | 5.5.19 | All | All | All |
| Application | Apache | Tomcat | 5.5.2 | All | All | All |
| Application | Apache | Tomcat | 5.5.20 | All | All | All |
| Application | Apache | Tomcat | 5.5.21 | All | All | All |
| Application | Apache | Tomcat | 5.5.22 | All | All | All |
| Application | Apache | Tomcat | 5.5.23 | All | All | All |
| Application | Apache | Tomcat | 5.5.24 | All | All | All |
| Application | Apache | Tomcat | 5.5.25 | All | All | All |
| Application | Apache | Tomcat | 5.5.26 | All | All | All |
| Application | Apache | Tomcat | 5.5.27 | All | All | All |
| Application | Apache | Tomcat | 5.5.28 | All | All | All |
| Application | Apache | Tomcat | 5.5.29 | All | All | All |
| Application | Apache | Tomcat | 5.5.3 | All | All | All |
| Application | Apache | Tomcat | 5.5.30 | All | All | All |
| Application | Apache | Tomcat | 5.5.31 | All | All | All |
| Application | Apache | Tomcat | 5.5.32 | All | All | All |
| Application | Apache | Tomcat | 5.5.33 | All | All | All |
| Application | Apache | Tomcat | 5.5.34 | All | All | All |
| Application | Apache | Tomcat | 5.5.35 | All | All | All |
| Application | Apache | Tomcat | 5.5.4 | All | All | All |
| Application | Apache | Tomcat | 5.5.5 | All | All | All |
| Application | Apache | Tomcat | 5.5.6 | All | All | All |
| Application | Apache | Tomcat | 5.5.7 | All | All | All |
| Application | Apache | Tomcat | 5.5.8 | All | All | All |
| Application | Apache | Tomcat | 5.5.9 | All | All | All |
| Application | Apache | Tomcat | 6.0 | All | All | All |
| Application | Apache | Tomcat | 6.0.0 | All | All | All |
| Application | Apache | Tomcat | 6.0.0 | alpha | All | All |
| Application | Apache | Tomcat | 6.0.1 | All | All | All |
| Application | Apache | Tomcat | 6.0.1 | alpha | All | All |
| Application | Apache | Tomcat | 6.0.10 | All | All | All |
| Application | Apache | Tomcat | 6.0.11 | All | All | All |
| Application | Apache | Tomcat | 6.0.12 | All | All | All |
| Application | Apache | Tomcat | 6.0.13 | All | All | All |
| Application | Apache | Tomcat | 6.0.14 | All | All | All |
| Application | Apache | Tomcat | 6.0.15 | All | All | All |
| Application | Apache | Tomcat | 6.0.16 | All | All | All |
| Application | Apache | Tomcat | 6.0.17 | All | All | All |
| Application | Apache | Tomcat | 6.0.18 | All | All | All |
| Application | Apache | Tomcat | 6.0.19 | All | All | All |
| Application | Apache | Tomcat | 6.0.2 | All | All | All |
| Application | Apache | Tomcat | 6.0.2 | alpha | All | All |
| Application | Apache | Tomcat | 6.0.2 | beta | All | All |
| Application | Apache | Tomcat | 6.0.20 | All | All | All |
| Application | Apache | Tomcat | 6.0.24 | All | All | All |
| Application | Apache | Tomcat | 6.0.26 | All | All | All |
| Application | Apache | Tomcat | 6.0.27 | All | All | All |
| Application | Apache | Tomcat | 6.0.28 | All | All | All |
| Application | Apache | Tomcat | 6.0.29 | All | All | All |
| Application | Apache | Tomcat | 6.0.3 | All | All | All |
| Application | Apache | Tomcat | 6.0.30 | All | All | All |
| Application | Apache | Tomcat | 6.0.31 | All | All | All |
| Application | Apache | Tomcat | 6.0.32 | All | All | All |
| Application | Apache | Tomcat | 6.0.33 | All | All | All |
| Application | Apache | Tomcat | 6.0.35 | All | All | All |
| Application | Apache | Tomcat | 6.0.4 | All | All | All |
| Application | Apache | Tomcat | 6.0.4 | alpha | All | All |
| Application | Apache | Tomcat | 6.0.5 | All | All | All |
| Application | Apache | Tomcat | 6.0.6 | All | All | All |
| Application | Apache | Tomcat | 6.0.6 | alpha | All | All |
| Application | Apache | Tomcat | 6.0.7 | All | All | All |
| Application | Apache | Tomcat | 6.0.7 | alpha | All | All |
| Application | Apache | Tomcat | 6.0.7 | beta | All | All |
| Application | Apache | Tomcat | 6.0.8 | All | All | All |
| Application | Apache | Tomcat | 6.0.8 | alpha | All | All |
| Application | Apache | Tomcat | 6.0.9 | All | All | All |
| Application | Apache | Tomcat | 6.0.9 | beta | All | All |
| Application | Apache | Tomcat | 7.0.0 | All | All | All |
| Application | Apache | Tomcat | 7.0.0 | beta | All | All |
| Application | Apache | Tomcat | 7.0.1 | All | All | All |
| Application | Apache | Tomcat | 7.0.10 | All | All | All |
| Application | Apache | Tomcat | 7.0.11 | All | All | All |
| Application | Apache | Tomcat | 7.0.12 | All | All | All |
| Application | Apache | Tomcat | 7.0.13 | All | All | All |
| Application | Apache | Tomcat | 7.0.14 | All | All | All |
| Application | Apache | Tomcat | 7.0.15 | All | All | All |
| Application | Apache | Tomcat | 7.0.16 | All | All | All |
| Application | Apache | Tomcat | 7.0.17 | All | All | All |
| Application | Apache | Tomcat | 7.0.18 | All | All | All |
| Application | Apache | Tomcat | 7.0.19 | All | All | All |
| Application | Apache | Tomcat | 7.0.2 | All | All | All |
| Application | Apache | Tomcat | 7.0.2 | beta | All | All |
| Application | Apache | Tomcat | 7.0.20 | All | All | All |
| Application | Apache | Tomcat | 7.0.21 | All | All | All |
| Application | Apache | Tomcat | 7.0.22 | All | All | All |
| Application | Apache | Tomcat | 7.0.23 | All | All | All |
| Application | Apache | Tomcat | 7.0.25 | All | All | All |
| Application | Apache | Tomcat | 7.0.28 | All | All | All |
| Application | Apache | Tomcat | 7.0.3 | All | All | All |
| Application | Apache | Tomcat | 7.0.4 | All | All | All |
| Application | Apache | Tomcat | 7.0.4 | beta | All | All |
| Application | Apache | Tomcat | 7.0.5 | All | All | All |
| Application | Apache | Tomcat | 7.0.6 | All | All | All |
| Application | Apache | Tomcat | 7.0.7 | All | All | All |
| Application | Apache | Tomcat | 7.0.8 | All | All | All |
| Application | Apache | Tomcat | 7.0.9 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM Security Bulletin: Multiple vulnerabilities in Rational Collaborative Lifecycle Management v4.0.1 (CVE-2012-5885, CVE-2012-5886, CVE-2012-5887) - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| openSUSE-SU-2012:1701-1: moderate: update for tomcat | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| openSUSE-SU-2012:1700-1: moderate: update for tomcat6 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Apache Tomcat® - Apache Tomcat 7 vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | tomcat.apache.org | Vendor Advisory |
| [Apache-SVN] Revision 1377807 | af854a3a-2127-422b-91ae-364da2661108 | svn.apache.org | |
| Apache Tomcat DIGEST Authentication Multiple Security Weaknesses | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| USN-1637-1: Tomcat vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Apache Tomcat - Apache Tomcat 5 vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | tomcat.apache.org | Vendor Advisory |
| openSUSE-SU-2013:0147-1: moderate: tomcat6 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Apache Tomcat® - Apache Tomcat 6 vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | tomcat.apache.org | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| [Apache-SVN] Revision 1380829 | af854a3a-2127-422b-91ae-364da2661108 | svn.apache.org | |
| [Apache-SVN] Revision 1392248 | af854a3a-2127-422b-91ae-364da2661108 | svn.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.