CVE-2012-3546

Impact:
Important
Public Date:
2012-12-04
Bugzilla:
883634: CVE-2012-3546 Tomcat/JBoss Web: Bypass of security constraints

The MITRE CVE dictionary describes this issue as:

org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when FORM authentication is used, allows remote attackers to bypass security-constraint checks by leveraging a previous setUserPrincipal call and then placing /j_security_check at the end of a URI.

Find out more about CVE-2012-3546 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

Tomcat 5.5 has reached the end of its supported upstream life-cycle, and the Apache Tomcat project no longer tests security flaws to determine whether they affect Tomcat 5.5. Red Hat has tested tomcat 5.5 as shipped with Red Hat Enterprise Linux 5 and JBoss Enterprise Web Server 1, and found that it is affected by this flaw. Patches for tomcat 5.5 to address this flaw have been provided.

CVSS v2 metrics

Base Score 5.5
Base Metrics AV:N/AC:L/Au:S/C:P/I:P/A:N
Access Vector Network
Access Complexity Low
Authentication Single
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact None

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 Server (tomcat6) RHSA-2013:0005 2013-01-03
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5 Server (jbossweb) RHSA-2013:0164 2013-01-15
Red Hat JBoss Enterprise Application Platform 5 for RHEL 6 Server (jbossweb) RHSA-2013:0191 2013-01-24
Red Hat JBoss Web Server 1.0 RHSA-2013:0157 2013-01-14
Red Hat JBoss Enterprise Application Platform 6 for RHEL 6 Server (jbossweb) RHSA-2013:0164 2013-01-15
Red Hat JBoss Portal 4.3 RHSA-2013:0151 2013-01-10
Red Hat JBoss Portal 5.2 RHSA-2013:0235 2013-02-04
Red Hat JBoss Enterprise Application Platform 6.0 RHSA-2013:0163 2013-01-15
Red Hat JBoss Web Platform 5 for RHEL 5 Server (jbossweb) RHSA-2013:0196 2013-01-24
Red Hat JBoss Web Platform 5 for RHEL 4 AS (jbossweb) RHSA-2013:0197 2013-01-24
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 Server (tomcat5) RHSA-2013:0641 2013-03-12
Red Hat Enterprise Linux 6 (tomcat6) RHSA-2013:0623 2013-03-11
Red Hat JBoss Enterprise Application Platform 4.3 RHSA-2013:0146 2013-01-08
Red Hat JBoss SOA Platform 4.3 RHSA-2013:0162 2013-01-15
Red Hat JBoss Enterprise Application Platform 5 for RHEL 5 Server (jbossweb) RHSA-2013:0192 2013-01-24
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 Server (tomcat6) RHSA-2013:0005 2013-01-03
Red Hat JBoss Enterprise Application Platform 5.2 RHSA-2013:0194 2013-01-24
Red Hat Enterprise Linux 5 (tomcat5) RHSA-2013:0640 2013-03-12
Red Hat JBoss Web Server 1.0 RHSA-2013:0642 2013-03-12
Red Hat JBoss Enterprise Application Platform 4.3.0 for RHEL 5 Server (jbossas) RHSA-2013:0147 2013-01-08
Red Hat JBoss Enterprise Application Platform 4.3.0 for RHEL 4 AS (jbossas) RHSA-2013:0147 2013-01-08
Red Hat JBoss SOA Platform 5.3 RHSA-2013:0235 2013-02-04
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 Server (tomcat6) RHSA-2013:0158 2013-01-14
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 Server (tomcat6) RHSA-2013:0158 2013-01-14
Red Hat JBoss Web Server 2.0 RHSA-2013:0004 2013-01-03
Red Hat JBoss Web Platform 5.2 RHSA-2013:0198 2013-01-24
JBoss Enterprise BRMS Platform 5.3 RHSA-2013:0221 2013-01-31
Red Hat JBoss Web Platform 5 for RHEL 6 Server (jbossweb) RHSA-2013:0195 2013-01-24
Red Hat JBoss Enterprise Application Platform 5 for RHEL 4 AS (jbossweb) RHSA-2013:0193 2013-01-24
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 Server (tomcat5) RHSA-2013:0641 2013-03-12
Unless explicitly stated as not affected, all previous versions of packages in any minor update stream of a product listed here should be assumed vulnerable, although may not have been subject to full analysis.
Last Modified

CVE description copyright © 2017, The MITRE Corporation