Lucene search

K
redhatcveRedhat.comRH:CVE-2019-17563
HistoryDec 20, 2019 - 6:38 p.m.

CVE-2019-17563

2019-12-2018:38:45
redhat.com
access.redhat.com
15

0.004 Low

EPSS

Percentile

73.2%

It was found that tomcat’s FORM authentication allowed a very small period in which an attacker could possibly force a victim to use a valid user session, or Session Fixation. While practical exploit of this issue is deemed highly improbable, an abundance of caution merits it be considered a flaw. The highest threat from this vulnerability is to system availability, but also threatens data confidentiality and integrity.