Apache Tomcat DIGEST Authentication Multiple Security Weaknesses
BID:56403
CVE-2012-5887 |Info
Apache Tomcat DIGEST Authentication Multiple Security Weaknesses
| Bugtraq ID: | 56403 |
| Class: | Unknown |
| CVE: |
CVE-2012-5885 CVE-2012-5886 CVE-2012-5887 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 06 2012 12:00AM |
| Updated: | May 23 2017 04:26PM |
| Credit: | Tilmann Kuhn and Tomcat Security Team |
| Vulnerable: |
VMWare vCenter Server 5.1 Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Redhat JBoss Enterprise Web Server EL6 2.0 Redhat JBoss Enterprise Web Server EL5 2.0 Redhat Jboss Enterprise Soa Platform 5.3.1 Redhat JBoss Enterprise Application Platform 6 EL6 Redhat JBoss Enterprise Application Platform 6 EL5 Redhat JBoss Data Grid 6.0.1 Redhat JBoss BRMS 5.3.1 Redhat Enterprise Linux Workstation Optional 6 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server Optional 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node Optional 6 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop Optional 6 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Juniper Network and Security Manager (NSM) 2012.2 Juniper Network and Security Manager (NSM) 2012.1 Juniper Network and Security Manager (NSM) 2011.4 Juniper Network and Security Manager (NSM) 2010.3 IBM Rational Team Concert 4.0.1 IBM Rational Team Concert 4.0 IBM Rational Requirements Composer 4.0.1 IBM Rational Requirements Composer 4.0 IBM Rational Collaborative Lifecycle Management Solution 4.0.1 IBM Rational Collaborative Lifecycle Management Solution 4.0 HP HP-UX Web Server Suite 3.22 HP HP-UX Web Server Suite 3.21 HP HP-UX Web Server Suite 3.18 HP HP-UX Web Server Suite 3.17 HP HP-UX B.11.31 HP HP-UX B.11.23 Gentoo Linux CTERA Networks CTERA Portal 3.1 CentOS CentOS 6 CentOS CentOS 5 Avaya one-X Client Enablement Service 6.1 SP2 Avaya one-X Client Enablement Service 6.1 Sp1 Avaya one-X Client Enablement Service 6.1 Avaya one-X Client Enablement Service 6.0 SP3 Avaya one-X Client Enablement Service 6.0 SP2 Avaya one-X Client Enablement Service 6.0 SP1 Avaya Aura System Manager 6.2.3 Avaya Aura System Manager 6.2 SP3 Avaya Aura System Manager 6.2 Avaya Aura System Manager 6.1.5 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 SP2 Avaya Aura System Manager 6.1 Sp1 Avaya Aura System Manager 6.1 Avaya Aura System Manager 6.0 SP1 Avaya Aura System Manager 6.0 Apache Tomcat 7.0.29 Apache Tomcat 7.0.28 Apache Tomcat 7.0.27 Apache Tomcat 7.0.26 Apache Tomcat 7.0.25 Apache Tomcat 7.0.24 Apache Tomcat 7.0.23 Apache Tomcat 7.0.16 Apache Tomcat 7.0.15 Apache Tomcat 7.0.14 Apache Tomcat 7.0.13 Apache Tomcat 7.0.12 Apache Tomcat 7.0.2 Apache Tomcat 7.0.1 Apache Tomcat 7.0 Apache Tomcat 6.0.35 Apache Tomcat 6.0.29 Apache Tomcat 6.0.28 Apache Tomcat 6.0.27 Apache Tomcat 6.0.26 Apache Tomcat 6.0.25 Apache Tomcat 6.0.24 Apache Tomcat 6.0.20 Apache Tomcat 6.0.18 Apache Tomcat 6.0.17 Apache Tomcat 6.0.16 Apache Tomcat 6.0.15 Apache Tomcat 6.0.14 Apache Tomcat 6.0.13 Apache Tomcat 6.0.12 Apache Tomcat 6.0.11 Apache Tomcat 6.0.10 Apache Tomcat 6.0.3 Apache Tomcat 6.0.2 Apache Tomcat 6.0.1 Apache Tomcat 6.0 Apache Tomcat 5.5.35 Apache Tomcat 5.5.34 Apache Tomcat 5.5.32 Apache Tomcat 5.5.30 Apache Tomcat 5.5.29 Apache Tomcat 5.5.28 Apache Tomcat 5.5.27 Apache Tomcat 5.5.26 Apache Tomcat 5.5.25 Apache Tomcat 5.5.24 Apache Tomcat 5.5.23 Apache Tomcat 5.5.22 Apache Tomcat 5.5.21 Apache Tomcat 5.5.20 Apache Tomcat 5.5.19 Apache Tomcat 5.5.18 Apache Tomcat 5.5.17 Apache Tomcat 5.5.16 Apache Tomcat 5.5.15 Apache Tomcat 5.5.14 Apache Tomcat 5.5.13 Apache Tomcat 5.5.12 Apache Tomcat 5.5.11 Apache Tomcat 5.5.10 Apache Tomcat 5.5.3 Apache Tomcat 5.5.2 Apache Tomcat 5.5.1 Apache Tomcat 5.5 Apache Tomcat 7.0.22 Apache Tomcat 7.0.21 Apache Tomcat 7.0.20 Apache Tomcat 7.0.19 Apache Tomcat 7.0.18 Apache Tomcat 7.0.17 Apache Tomcat 7.0.11 Apache Tomcat 7.0.10 Apache Tomcat 6.0.33 Apache Tomcat 6.0.32 Apache Tomcat 6.0.31 Apache Tomcat 6.0.30 Apache Tomcat 5.5.33 Apache Tomcat 0 |
| Not Vulnerable: |
VMWare vCenter Server 5.1 Update 1 Redhat JBoss Enterprise Application Platform 6.0.1 Redhat JBoss Data Grid 6.1 CTERA Networks CTERA Portal 3.2.28 CTERA Networks CTERA Portal 3.1.39 Avaya one-X Client Enablement Service 6.1 SP3 Avaya Aura System Manager 6.3 Apache Tomcat 7.0.30 Apache Tomcat 6.0.36 Apache Tomcat 5.5.36 |
Discussion
Apache Tomcat DIGEST Authentication Multiple Security Weaknesses
Apache Tomcat is prone to multiple security weaknesses.
Successful exploits may allow an attacker to bypass certain security restrictions and perform unauthorized actions.
These issues affect the following versions:
Tomcat 7.0.0 through 7.0.29
Tomcat 6.0.0 through 6.0.35
Tomcat 5.5.0 through 5.5.35
Apache Tomcat is prone to multiple security weaknesses.
Successful exploits may allow an attacker to bypass certain security restrictions and perform unauthorized actions.
These issues affect the following versions:
Tomcat 7.0.0 through 7.0.29
Tomcat 6.0.0 through 6.0.35
Tomcat 5.5.0 through 5.5.35
Exploit / POC
Apache Tomcat DIGEST Authentication Multiple Security Weaknesses
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apache Tomcat DIGEST Authentication Multiple Security Weaknesses
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5
-
Mandriva tomcat5-5.5.28-0.5.0.5mdvmes5.2.noarch.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva tomcat5-admin-webapps-5.5.28-0.5.0.5mdvmes5.2.noarch.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva tomcat5-common-lib-5.5.28-0.5.0.5mdvmes5.2.noarch.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva tomcat5-jasper-5.5.28-0.5.0.5mdvmes5.2.noarch.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva tomcat5-jasper-eclipse-5.5.28-0.5.0.5mdvmes5.2.noarch.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva tomcat5-jasper-javadoc-5.5.28-0.5.0.5mdvmes5.2.noarch.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva tomcat5-jsp-2.0-api-5.5.28-0.5.0.5mdvmes5.2.noarch.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva tomcat5-jsp-2.0-api-javadoc-5.5.28-0.5.0.5mdvmes5.2.noarch.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva tomcat5-server-lib-5.5.28-0.5.0.5mdvmes5.2.noarch.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva tomcat5-servlet-2.4-api-5.5.28-0.5.0.5mdvmes5.2.noarch.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva tomcat5-servlet-2.4-api-javadoc-5.5.28-0.5.0.5mdvmes5.2.noarch.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva tomcat5-webapps-5.5.28-0.5.0.5mdvmes5.2.noarch.rpm
http://www.mandriva.com/en/downloads/
References
Apache Tomcat DIGEST Authentication Multiple Security Weaknesses
References:
References:
- 2013-11 Security Bulletin: Network and Security Manager: Apache Tomcat security (Juniper Networks)
- Apache Tomcat 5.x vulnerabilities (Apache)
- Apache Tomcat 6.x vulnerabilities (Apache)
- Apache Tomcat 7.x vulnerabilities (Apache)
- Apache Tomcat Homepage (Apache)
- HPSBUX02866 SSRT101139 rev.1 - HP-UX Running Apache, Remote Denial of Service (D (HP)
- Multiple Tomcat vulnerabilities in Oracle Health Sciences Clinical Development C (Oracle)
- Multiple vulnerabilities in CTERA Portal (SEC Consult Vulnerability Lab)
- Multiple vulnerabilities in Rational Collaborative Lifecycle Management v4.0.1 (IBM)
- ASA-2013-172: tomcat5 security update (RHSA-2013-0640) (Avaya)
- HPSBUX02860 SSRT101146 rev.1 - HP-UX Apache Running Tomcat Servlet Engine, Remot (HP)
- Important: JBoss Data Grid 6.1.0 update (Red Hat)
- Important: JBoss Enterprise SOA Platform 5.3.1 update (Red Hat)
- Moderate: jbossweb security update (Red Hat)
- Moderate: tomcat6 security update (Red Hat)
- Security Advisory Moderate: jbossweb security update (Red Hat)
- VMware security updates for vCenter Server (VMware)