Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7761
HistoryNov 13, 2018 - 5:10 a.m.

Session Hijacking

2018-11-1305:10:16
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.066 Low

EPSS

Percentile

93.8%

tomcat-util is vulnerable to session hijacking attacks. The vulnerability exists due to tomcat-util incorrectly treating single quotes as delimiters in cookies, allowing sensitive information such as session ID to be leaked. This issue is also CVE-2007-3385.

References