Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12242
HistoryJan 15, 2019 - 9:14 a.m.

Information Disclosure

2019-01-1509:14:42
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

EPSS

0.009

Percentile

83.2%

Tomcat is vulnerable to information disclosure. It is possible because it does not prevent the leveraging use of requestedSessionSSL field, allowing the reuse of the same session ID for the next request using that Request object. The vulnerability is not easy to set up as the client because it needs the use of correct Request object.