VDB
RHSA-2012:0679
RHSA-2012:0679
PUBLISHED
CVSS 4.300000190734863 MEDIUM
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not have the expected countermeasures against replay attacks, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, related to lack of checking of nonce (aka server nonce) and nc (aka nonce-count or client nonce count) values.
Risk Scores
CVSS 2.0
4.300000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss Web Server 1.0 |
Timeline
- May 21, 2012 CVE Published
- Jan 28, 2026 CVE Updated
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2012:0679 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- http://tomcat.apache.org/security-5.html advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=webserver&downloadType=securityPatches&version=1.0.2 advisory
- https://issues.jboss.org/browse/JBPAPP-4873 advisory
- https://issues.jboss.org/browse/JBPAPP-6133 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=717013 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=720948 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=734868 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=741401 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=750521 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=783359 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2012/rhsa-2012_0679.json advisory
- https://access.redhat.com/security/cve/CVE-2011-1184 advisory
- https://www.cve.org/CVERecord?id=CVE-2011-1184 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2011-1184 advisory
- https://access.redhat.com/security/cve/CVE-2011-2204 advisory
- https://www.cve.org/CVERecord?id=CVE-2011-2204 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2011-2204 advisory
- https://access.redhat.com/security/cve/CVE-2011-2526 advisory
…and 20 more