Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22206
HistoryDec 19, 2019 - 8:29 a.m.

Session Fixation

2019-12-1908:29:44
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.004 Low

EPSS

Percentile

73.2%

Apache Tomcat Catalina is vulnerable to session fixation attack. The vulnerability exists because there is a flaw in checking whether an authentication information (authType and principal) are cached for a session and the validity of a session token in request when cache==false, allowing an attacker to impersonate the user.

References