FlawAtlas
Search the atlas
CVE-2015-5346 High

Improper Neutralization of Input During Web Page Generation in Apache Tomcat

Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.

Exploit probability 10.6%
Published May 14, 2022
Required by Not available
Last source change March 11, 2024

02 / AFFECTED SOFTWARE

Affected packages

Maven org.apache.tomcat:tomcat

42 explicit affected versions

04 / EVIDENCE

Source records

Open Source Vulnerabilities GHSA-jrcp-c39h-r29x

Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.

View original source

05 / REFERENCES

Further evidence