Lucene search

K
githubGitHub Advisory DatabaseGHSA-6GJJ-C5MJ-4CVP
HistoryMay 14, 2022 - 1:10 a.m.

Improper Input Validation in Apache Tomcat

2022-05-1401:10:35
CWE-20
GitHub Advisory Database
github.com
16
apache tomcat
input validation
session fixation

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS

0.004

Percentile

73.0%

org/apache/catalina/connector/CoyoteAdapter.java in Apache Tomcat 6.0.33 through 6.0.37 does not consider the disableURLRewriting setting when handling a session ID in a URL, which allows remote attackers to conduct session fixation attacks via a crafted URL.

Affected configurations

Vulners
Node
org.apache.tomcattomcatRange6.0.33โ€“6.0.38
VendorProductVersionCPE
org.apache.tomcattomcat*cpe:2.3:a:org.apache.tomcat:tomcat:*:*:*:*:*:*:*:*

References

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS

0.004

Percentile

73.0%