CVE-2012-3546 Apache Tomcat Bypass of...
FromSent OnAttachments
Mark Thomas Dec 4, 2012 11:47 am 
Subject:CVE-2012-3546 Apache Tomcat Bypass of security constraints
From:Mark Thomas (
Date:Dec 4, 2012 11:47:28 am


CVE-2012-3546 Apache Tomcat Bypass of security constraints

Severity: Important

Vendor: The Apache Software Foundation

Versions Affected: - - Tomcat 7.0.0 to 7.0.29 - - Tomcat 6.0.0 to 6.0.35 Earlier unsupported versions may also be affected

Description: When using FORM authentication it was possible to bypass the security constraint checks in the FORM authenticator by appending "/j_security_check" to the end of the URL if some other component (such as the Single-Sign-On valve) had called request.setUserPrincipal() before the call to FormAuthenticator#authenticate().

Mitigation: Users of affected versions should apply one of the following mitigations: - - Tomcat 7.0.x users should upgrade to 7.0.30 or later - - Tomcat 6.0.x users should upgrade to 6.0.36 or later

Credit: This issue was identified by The Tomcat security team

