Lucene search

K
ubuntucveUbuntu.comUB:CVE-2013-2067
HistoryMay 10, 2013 - 12:00 a.m.

CVE-2013-2067

2013-05-1000:00:00
ubuntu.com
ubuntu.com
22

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.012

Percentile

85.1%

java/org/apache/catalina/authenticator/FormAuthenticator.java in the form
authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x
before 7.0.33 does not properly handle the relationships between
authentication requirements and sessions, which allows remote attackers to
inject a request into a session by sending this request during completion
of the login form, a variant of a session fixation attack.

OSVersionArchitecturePackageVersionFilename
ubuntu10.04noarchtomcat6<ย 6.0.24-2ubuntu1.13UNKNOWN
ubuntu12.04noarchtomcat6<ย 6.0.35-1ubuntu3.3UNKNOWN
ubuntu12.10noarchtomcat6<ย 6.0.35-5ubuntu0.1UNKNOWN
ubuntu12.10noarchtomcat7<ย 7.0.30-0ubuntu1.2UNKNOWN

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.012

Percentile

85.1%