CVE-2012-3546
CVE-2012-3546
org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when FORM authentication is used, allows remote attackers to bypass security-constraint checks by leveraging a previous setUserPrincipal call and then placing /j_security_check at the end of a URI.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://archives.neohapsis.com/archives/bugtraq/2012-12/0044.htmlhttp://lists.opensuse.org/opensuse-updates/2012-12/msg00089.htmlhttp://lists.opensuse.org/opensuse-updates/2012-12/msg00090.htmlhttp://lists.opensuse.org/opensuse-updates/2013-01/msg00037.htmlhttp://marc.info/?l=bugtraq&m=136612293908376&w=2http://marc.info/?l=bugtraq&m=139344343412337&w=2http://rhn.redhat.com/errata/RHSA-2013-0004.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0005.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0146.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0147.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0151.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0157.html