CVE-2013-2067Medium· 6.8▾ Sunlitjava/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 37.4 · likelihood 1.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
7.1%
java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.
tomcat = 6.0.21tomcat = 6.0.24tomcat = 6.0.26tomcat = 6.0.27tomcat = 6.0.28tomcat = 6.0.29tomcat = 6.0.30tomcat = 6.0.31tomcat = 6.0.32tomcat = 6.0.33tomcat = 6.0.35tomcat = 6.0.36tomcat = 7.0.0tomcat = 7.0.1tomcat = 7.0.2tomcat = 7.0.3tomcat = 7.0.4tomcat = 7.0.5tomcat = 7.0.6tomcat = 7.0.7tomcat = 7.0.8tomcat = 7.0.9tomcat = 7.0.10tomcat = 7.0.11tomcat = 7.0.12tomcat = 7.0.13tomcat = 7.0.14tomcat = 7.0.15tomcat = 7.0.16tomcat = 7.0.17tomcat = 7.0.18tomcat = 7.0.19tomcat = 7.0.20tomcat = 7.0.21tomcat = 7.0.22tomcat = 7.0.23tomcat = 7.0.25tomcat = 7.0.28tomcat = 7.0.30tomcat = 7.0.32Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2012-5887Medium· 5.0The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values in conjunction with enforcement of proper credentials, whi…
CVE-2012-5886Medium· 5.0The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches information about the authenticated user within the session state, which makes it easier for remot…
CVE-2013-4590Medium· 4.3Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, o…
CVE-2013-4444Medium· 6.8Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.File code and a custom JMX configuration, allows remote attackers to execute arbitrary code by uploading and acce…
CVE-2013-4286Medium· 5.8Apache Tomcat before 6.0.39, 7.x before 7.0.47, and 8.x before 8.0.0-RC3, when an HTTP connector or AJP connector is used, does not properly handle certain inconsistent HTTP request headers, which allows remote attackers to trigger incor…
CVE-2013-4322Medium· 4.3Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 processes chunked transfer coding without properly handling (1) a large total amount of chunked data or (2) whitespace characters in an HTTP header value within a …