java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Tomcat | — | Upgrade Apache Tomcat to 6.0.37Upgrade Apache Tomcat to 7.0.33Upgrade Apache Tomcat to the latest available version | Jun 1, 2013 | Jun 1, 2013 |
| Centos_linux | — | Upgrade tomcat6-libUpgrade tomcat6-webappsUpgrade tomcat6-el-2.1-apiUpgrade tomcat6-jsp-2.1-apiUpgrade tomcat6-javadocUpgrade tomcat6Upgrade tomcat6-servlet-2.5-apiUpgrade tomcat6-docs-webappUpgrade tomcat6-admin-webapps | Dec 1, 2016 | Jun 1, 2013 |
| Gentoo Linux | — | Upgrade www-servers/tomcat. | Oct 30, 2017 | Jun 1, 2013 |
| Oracle Solaris | — | Upgrade web/java-servlet/tomcat/tomcat-examples to version 6.0.37-0.175.1.11.0.4.0 on Solaris 11.1Upgrade web/java-servlet/tomcat to version 6.0.37-0.175.1.11.0.4.0 on Solaris 11.1 | May 29, 2017 | Jun 1, 2013 |
| Oracle_linux | — | Upgrade tomcat6-webappsUpgrade tomcat6-admin-webappsUpgrade tomcat6-javadocUpgrade tomcat6-docs-webappUpgrade tomcat6-jsp-2.1-apiUpgrade tomcat6-servlet-2.5-apiUpgrade tomcat6Upgrade tomcat6-el-2.1-apiUpgrade tomcat6-lib | Oct 16, 2024 | Jun 1, 2013 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | May 10, 2013 |
| Suse | — | Upgrade tomcat-jsp-2_2-apiUpgrade tomcat-javadocUpgrade tomcatUpgrade tomcat-servlet-3_0-apiUpgrade tomcat-el-2_2-apiUpgrade tomcat-admin-webappsUpgrade tomcat-libUpgrade tomcat-docs-webappUpgrade tomcat-webappsUpgrade tomcat-jsvc | Dec 12, 2013 | Jun 1, 2013 |
| Ubuntu | — | Upgrade libtomcat7-javaUpgrade libtomcat6-java | Nov 8, 2024 | Jun 1, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub