VDB
RHSA-2012%3A0041
RHSA-2012%3A0041
PUBLISHED
CVSS 4.300000190734863 MEDIUM
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not have the expected countermeasures against replay attacks, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, related to lack of checking of nonce (aka server nonce) and nc (aka nonce-count or client nonce count) values.
Risk Scores
CVSS 2.0
4.300000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss Enterprise Application Platform 4.3 |
Timeline
- Jan 19, 2012 CVE Published
- Jan 28, 2026 CVE Updated
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2012:0041 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=720948 issue
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=appplatform&downloadType=securityPatches&version=4.3.0.GA_CP10 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=741401 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=750521 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2012/rhsa-2012_0041.json advisory
- https://access.redhat.com/security/cve/CVE-2011-1184 advisory
- https://www.cve.org/CVERecord?id=CVE-2011-1184 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2011-1184 advisory
- https://access.redhat.com/security/cve/CVE-2011-2526 advisory
- https://www.cve.org/CVERecord?id=CVE-2011-2526 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2011-2526 advisory
- https://access.redhat.com/security/cve/CVE-2011-4858 advisory
- https://www.cve.org/CVERecord?id=CVE-2011-4858 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2011-4858 advisory
- https://access.redhat.com/security/cve/CVE-2011-5062 advisory
- https://www.cve.org/CVERecord?id=CVE-2011-5062 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2011-5062 advisory
- https://access.redhat.com/security/cve/CVE-2011-5063 advisory
…and 5 more