VDB

RHSA-2013:0163

RHSA-2013:0163 PUBLISHED CVSS 5.5 MEDIUM

org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when FORM authentication is used, allows remote attackers to bypass security-constraint checks by leveraging a previous setUserPrincipal call and then placing /j_security_check at the end of a URI.

Risk Scores

CVSS 2.0
5.5

Affected Products

VendorProductVersions
Red HatRed Hat JBoss Enterprise Application Platform 6.0

Timeline

  • Jan 15, 2013 CVE Published
  • May 14, 2026 CVE Updated
  • May 15, 2026 Distribution Patch
  • May 15, 2026 Distribution Patch
  • May 15, 2026 Security Advisory
  • May 15, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›