The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 tracks cnonce (aka client nonce) values instead of nonce (aka server nonce) and nc (aka nonce-count) values, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, a different vulnerability than CVE-2011-1184.
References
Link Providers
https://www.spirityenterprise.com/virtual-ciso spirity
http://lists.opensuse.org/opensuse-updates/2012-12/msg00089.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-updates/2012-12/msg00090.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-updates/2013-01/msg00037.html cve-icon cve-icon
http://marc.info/?l=bugtraq&m=136485229118404&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=136612293908376&w=2 cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2013-0623.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2013-0629.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2013-0631.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2013-0632.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2013-0633.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2013-0640.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2013-0647.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2013-0648.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2013-0726.html cve-icon cve-icon
http://secunia.com/advisories/51371 cve-icon cve-icon
http://svn.apache.org/viewvc?view=revision&revision=1377807 cve-icon cve-icon
http://svn.apache.org/viewvc?view=revision&revision=1380829 cve-icon cve-icon
http://svn.apache.org/viewvc?view=revision&revision=1392248 cve-icon cve-icon
http://tomcat.apache.org/security-5.html cve-icon cve-icon
http://tomcat.apache.org/security-6.html cve-icon cve-icon
http://tomcat.apache.org/security-7.html cve-icon cve-icon
http://www-01.ibm.com/support/docview.wss?uid=swg21626891 cve-icon cve-icon
http://www.securityfocus.com/bid/56403 cve-icon cve-icon
http://www.ubuntu.com/usn/USN-1637-1 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/80408 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2012-5885 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19432 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2012-5885 cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T21:21:27.917Z

Reserved: 2012-11-17T00:00:00

Link: CVE-2012-5885

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2012-11-17T19:55:02.673

Modified: 2025-04-11T00:51:21.963

Link: CVE-2012-5885

cve-icon Redhat

Severity : Moderate

Publid Date: 2012-11-05T00:00:00Z

Links: CVE-2012-5885 - Bugzilla