Lucene search

K
redhatRedHatRHSA-2013:0157
HistoryJan 14, 2013 - 12:00 a.m.

(RHSA-2013:0157) Important: tomcat6 security update

2013-01-1400:00:00
access.redhat.com
21

0.003 Low

EPSS

Percentile

69.3%

Apache Tomcat is a servlet container.

It was found that when an application used FORM authentication, along with
another component that calls request.setUserPrincipal() before the call to
FormAuthenticator#authenticate() (such as the Single-Sign-On valve), it was
possible to bypass the security constraint checks in the FORM authenticator
by appending โ€œ/j_security_checkโ€ to the end of a URL. A remote attacker
with an authenticated session on an affected application could use this
flaw to circumvent authorization controls, and thereby access resources not
permitted by the roles associated with their authenticated session.
(CVE-2012-3546)

Warning: Before applying the update, back up your existing JBoss Enterprise
Web Server installation (including all applications and configuration
files).

All users of JBoss Enterprise Web Server 1.0.2 as provided from the Red Hat
Customer Portal are advised to apply this update.