CVE-2013-2051
09.07.2013, 17:55
The Tomcat 6 DIGEST authentication functionality as used in Red Hat Enterprise Linux 6 allows remote attackers to bypass intended access restrictions by performing a replay attack after a nonce becomes stale. NOTE: this issue is due to an incomplete fix for CVE-2012-5887.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| redhat | enterprise_linux | 6.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| tomcat6 |
| ||
| tomcat6-admin-webapps |
| ||
| tomcat6-docs-webapp |
| ||
| tomcat6-el-2.1-api |
| ||
| tomcat6-javadoc |
| ||
| tomcat6-jsp-2.1-api |
| ||
| tomcat6-lib |
| ||
| tomcat6-servlet-2.5-api |
| ||
| tomcat6-webapps |
|
Common Weakness Enumeration