CVE

Id
52974  
CVE No.
CVE-2011-5062  
Status
Candidate  
Description
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qop values, which might allow remote attackers to bypass intended integrity-protection requirements via a qop=auth value, a different vulnerability than CVE-2011-1184.  
Phase
Assigned (20120114)  
Votes
None (candidate not yet proposed)  
Comments