ISOMAN

CVE

CVE-2015-5346

Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.

Severity
HIGH
CVSS
8.1
Published
Modified

Linked Releases

References

  1. http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00047.html
  2. http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00069.html
  3. http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00085.html
  4. http://packetstormsecurity.com/files/135890/Apache-Tomcat-Session-Fixation.html
  5. http://rhn.redhat.com/errata/RHSA-2016-1089.html
  6. http://rhn.redhat.com/errata/RHSA-2016-2046.html
  7. http://rhn.redhat.com/errata/RHSA-2016-2807.html
  8. http://rhn.redhat.com/errata/RHSA-2016-2808.html
  9. http://seclists.org/bugtraq/2016/Feb/143
  10. http://svn.apache.org/viewvc?view=revision&revision=1713184
  11. http://svn.apache.org/viewvc?view=revision&revision=1713185
  12. http://svn.apache.org/viewvc?view=revision&revision=1713187
  13. http://svn.apache.org/viewvc?view=revision&revision=1723414
  14. http://svn.apache.org/viewvc?view=revision&revision=1723506
  15. http://tomcat.apache.org/security-7.html
  16. http://tomcat.apache.org/security-8.html
  17. http://tomcat.apache.org/security-9.html
  18. http://www.debian.org/security/2016/dsa-3530
  19. http://www.debian.org/security/2016/dsa-3552
  20. http://www.debian.org/security/2016/dsa-3609