Apache Tomcat CVE-2012-3546 Weak Authentication Vulnerability
Description
When using FORM authentication it was possible to bypass the security constraint checks in the FORM authenticator by appending /j_security_check to the end of the URL if some other component (such as the Single-Sign-On valve) had called request.setUserPrincipal() before the call to FormAuthenticator#authenticate().
Affected Applications
Apache Tomcat