FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2012-3546

This CVE name corresponds to:

Entered Topic
2012-12-04 tomcat -- bypass of security constraints

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2012-3546
Phase Assigned(20120614)

Description

org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when FORM authentication is used, allows remote attackers to bypass security-constraint checks by leveraging a previous setUserPrincipal call and then placing /j_security_check at the end of a URI.

References

Source Reference
BUGTRAQ 20121204 CVE-2012-3546 Apache Tomcat Bypass of security constraints
CONFIRM http://svn.apache.org/viewvc/tomcat/tc7.0.x/trunk/java/org/apache/catalina/realm/RealmBase.java?r1=1377892&r2=1377891&pathrev=1377892
CONFIRM http://svn.apache.org/viewvc/tomcat/tc7.0.x/trunk/webapps/docs/changelog.xml?r1=1377892&r2=1377891&pathrev=1377892
CONFIRM http://svn.apache.org/viewvc?view=revision&revision=1377892
CONFIRM http://tomcat.apache.org/security-6.html
CONFIRM http://tomcat.apache.org/security-7.html
HP HPSBMU02873
HP SSRT101182
HP HPSBST02955
REDHAT RHSA-2013:0146
REDHAT RHSA-2013:0147
REDHAT RHSA-2013:0151
REDHAT RHSA-2013:0157
REDHAT RHSA-2013:0158
REDHAT RHSA-2013:0164
REDHAT RHSA-2013:0191
REDHAT RHSA-2013:0192
REDHAT RHSA-2013:0193
REDHAT RHSA-2013:0194
REDHAT RHSA-2013:0195
REDHAT RHSA-2013:0196
REDHAT RHSA-2013:0197
REDHAT RHSA-2013:0198
REDHAT RHSA-2013:0221
REDHAT RHSA-2013:0162
REDHAT RHSA-2013:0163
REDHAT RHSA-2013:0235
REDHAT RHSA-2013:0004
REDHAT RHSA-2013:0623
REDHAT RHSA-2013:0640
REDHAT RHSA-2013:0641
REDHAT RHSA-2013:0642
REDHAT RHSA-2013:0005
SUSE openSUSE-SU-2012:1700
SUSE openSUSE-SU-2012:1701
SUSE openSUSE-SU-2013:0147
UBUNTU USN-1685-1
OVAL oval:org.mitre.oval:def:19305
SECTRACK 1027833
SECUNIA 51984
SECUNIA 52054
SECUNIA 57126