Get real-time updates on Telegram
CVE-2012-5887: tomcat from 5.5.0 (inclusive), before 5.5.36 (exclusive), from 6.0.0 (inclusive), before 6.0.36 (exclusive), from…
CVE-2012-5887. CVSS 2.0 base score 5.0 (MEDIUM, NVD). EPSS 0.12098 (percentile 0.96053), scored 2026-10-08.
Affected technology
tomcat · from 5.5.0 (inclusive), before 5.5.36 (exclusive)
apache
tomcat · from 6.0.0 (inclusive), before 6.0.36 (exclusive)
apache
tomcat · from 7.0.0 (inclusive), before 7.0.30 (exclusive)
apache
n/a · n/a
Vendor not specified by the source
Description’s affected range: before 5.5.36
Component: Not specified by the source
Attack conditions (NVD, CVSS 2.0): Network (remote)
What an attacker can do
NVD’s CVSS 2.0 assessment (base score 5.0/10) rates confidentiality and availability impact as none; integrity impact as partial. The description does not specify what an attacker can achieve beyond these rated impacts.
- CWE
- CWE-287
- CCR priority
- 23.0 /100 (P4)
- CVSS 2.0
- 5.0 /10 · CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:P/A:N · NVD
- EPSS
- 0.12098 · percentile 0.96057 · 2026-10-09
- KEV
- no
Provenance
- FIRST EPSS daily exploit-probability · Source record · observed 2026-10-09 21:11:27.988868+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-09 21:08:49.498434+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2012-5887.html