CVE-2012-5887EPSS p96.1%

CVE-2012-5887CVE-2012-5887

apache / tomcat

Description

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values in conjunction with enforcement of proper credentials, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests.

Scoring

CVSS 5.0 ()
VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS12.10% probability of exploitation · percentile 96.1% · 2026-10-10T12:00:23Z
Last modified2026-10-09
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.