Lucene search

K
tomcatApache TomcatTOMCAT:FDED4DC7FD0A2FD3D2AAFA22A540F793
HistoryFeb 08, 2007 - 12:00 a.m.

Fixed in Apache Tomcat 6.0.9

2007-02-0800:00:00
Apache Tomcat
tomcat.apache.org
16

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

0.002 Low

EPSS

Percentile

60.8%

Moderate: Session hi-jacking CVE-2008-0128

When using the SingleSignOn Valve via https the Cookie JSESSIONIDSSO is transmitted without the “secure” attribute, resulting in it being transmitted to any content that is - by purpose or error - requested via http from the same server.

Affects: 6.0.0-6.0.8

CPENameOperatorVersion
apache tomcatge6.0.0
apache tomcatle6.0.8

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

0.002 Low

EPSS

Percentile

60.8%