---
id: CVE-2013-2067
title: >-
  java/org/apache/catalina/authenticator/FormAuthenticator.java in the form
  authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before
  7.0.33 does not properly handle the relationships between authentication
  requirements …
summary: >-
  java/org/apache/catalina/authenticator/FormAuthenticator.java in the form
  authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before
  7.0.33 does not properly handle the relationships between authentication
  requirements …
severity: medium
cvss: 6.8
cvssVector: 'AV:N/AC:M/Au:N/C:P/I:P/A:P'
cwe:
  - CWE-287
vendor: apache
product: tomcat
affected:
  - tomcat = 6.0.21
  - tomcat = 6.0.24
  - tomcat = 6.0.26
  - tomcat = 6.0.27
  - tomcat = 6.0.28
  - tomcat = 6.0.29
  - tomcat = 6.0.30
  - tomcat = 6.0.31
  - tomcat = 6.0.32
  - tomcat = 6.0.33
  - tomcat = 6.0.35
  - tomcat = 6.0.36
  - tomcat = 7.0.0
  - tomcat = 7.0.1
  - tomcat = 7.0.2
  - tomcat = 7.0.3
  - tomcat = 7.0.4
  - tomcat = 7.0.5
  - tomcat = 7.0.6
  - tomcat = 7.0.7
  - tomcat = 7.0.8
  - tomcat = 7.0.9
  - tomcat = 7.0.10
  - tomcat = 7.0.11
  - tomcat = 7.0.12
  - tomcat = 7.0.13
  - tomcat = 7.0.14
  - tomcat = 7.0.15
  - tomcat = 7.0.16
  - tomcat = 7.0.17
  - tomcat = 7.0.18
  - tomcat = 7.0.19
  - tomcat = 7.0.20
  - tomcat = 7.0.21
  - tomcat = 7.0.22
  - tomcat = 7.0.23
  - tomcat = 7.0.25
  - tomcat = 7.0.28
  - tomcat = 7.0.30
  - tomcat = 7.0.32
published: '2013-06-01'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T20:17:06.897'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2013-2067'
references:
  - url: 'http://archives.neohapsis.com/archives/bugtraq/2013-05/0041.html'
    label: secalert@redhat.com
  - url: 'http://rhn.redhat.com/errata/RHSA-2013-0833.html'
    label: secalert@redhat.com
  - url: 'http://rhn.redhat.com/errata/RHSA-2013-0834.html'
    label: secalert@redhat.com
  - url: 'http://rhn.redhat.com/errata/RHSA-2013-0839.html'
    label: secalert@redhat.com
  - url: 'http://rhn.redhat.com/errata/RHSA-2013-0964.html'
    label: secalert@redhat.com
  - url: 'http://rhn.redhat.com/errata/RHSA-2013-1437.html'
    label: secalert@redhat.com
  - url: >-
      http://svn.apache.org/viewvc/tomcat/tc6.0.x/trunk/java/org/apache/catalina/authenticator/FormAuthenticator.java?r1=1417891&r2=1417890&pathrev=1417891
    label: secalert@redhat.com
  - url: >-
      http://svn.apache.org/viewvc/tomcat/tc7.0.x/trunk/java/org/apache/catalina/authenticator/FormAuthenticator.java?r1=1408044&r2=1408043&pathrev=1408044
    label: secalert@redhat.com
  - url: 'http://svn.apache.org/viewvc?view=revision&revision=1408044'
    label: secalert@redhat.com
  - url: 'http://svn.apache.org/viewvc?view=revision&revision=1417891'
    label: secalert@redhat.com
  - url: 'http://tomcat.apache.org/security-6.html'
    label: secalert@redhat.com
  - url: 'http://tomcat.apache.org/security-7.html'
    label: secalert@redhat.com
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
    label: secalert@redhat.com
  - url: 'http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html'
    label: secalert@redhat.com
  - url: 'http://www.securityfocus.com/bid/59799'
    label: secalert@redhat.com
  - url: 'http://www.securityfocus.com/bid/64758'
    label: secalert@redhat.com
  - url: 'http://www.ubuntu.com/usn/USN-1841-1'
    label: secalert@redhat.com
  - url: >-
      https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113%40%3Cdev.tomcat.apache.org%3E
    label: secalert@redhat.com
  - url: >-
      https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b%40%3Cdev.tomcat.apache.org%3E
    label: secalert@redhat.com
  - url: >-
      https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95%40%3Cdev.tomcat.apache.org%3E
    label: secalert@redhat.com
  - url: >-
      https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb%40%3Cdev.tomcat.apache.org%3E
    label: secalert@redhat.com
  - url: >-
      https://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c%40%3Cdev.tomcat.apache.org%3E
    label: secalert@redhat.com
  - url: >-
      https://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b%40%3Cdev.tomcat.apache.org%3E
    label: secalert@redhat.com
  - url: 'http://archives.neohapsis.com/archives/bugtraq/2013-05/0041.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2013-0833.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2013-0834.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2013-0839.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2013-0964.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2013-1437.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://svn.apache.org/viewvc/tomcat/tc6.0.x/trunk/java/org/apache/catalina/authenticator/FormAuthenticator.java?r1=1417891&r2=1417890&pathrev=1417891
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://svn.apache.org/viewvc/tomcat/tc7.0.x/trunk/java/org/apache/catalina/authenticator/FormAuthenticator.java?r1=1408044&r2=1408043&pathrev=1408044
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://svn.apache.org/viewvc?view=revision&revision=1408044'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://svn.apache.org/viewvc?view=revision&revision=1417891'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://tomcat.apache.org/security-6.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://tomcat.apache.org/security-7.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securityfocus.com/bid/59799'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securityfocus.com/bid/64758'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.ubuntu.com/usn/USN-1841-1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.07147
epssPercentile: 0.94124
ingestedAt: '2026-10-09T21:12:42.312Z'
---

## Overview

java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.

## Affected

- `tomcat = 6.0.21`
- `tomcat = 6.0.24`
- `tomcat = 6.0.26`
- `tomcat = 6.0.27`
- `tomcat = 6.0.28`
- `tomcat = 6.0.29`
- `tomcat = 6.0.30`
- `tomcat = 6.0.31`
- `tomcat = 6.0.32`
- `tomcat = 6.0.33`
- `tomcat = 6.0.35`
- `tomcat = 6.0.36`
- `tomcat = 7.0.0`
- `tomcat = 7.0.1`
- `tomcat = 7.0.2`
- `tomcat = 7.0.3`
- `tomcat = 7.0.4`
- `tomcat = 7.0.5`
- `tomcat = 7.0.6`
- `tomcat = 7.0.7`
- `tomcat = 7.0.8`
- `tomcat = 7.0.9`
- `tomcat = 7.0.10`
- `tomcat = 7.0.11`
- `tomcat = 7.0.12`
- `tomcat = 7.0.13`
- `tomcat = 7.0.14`
- `tomcat = 7.0.15`
- `tomcat = 7.0.16`
- `tomcat = 7.0.17`
- `tomcat = 7.0.18`
- `tomcat = 7.0.19`
- `tomcat = 7.0.20`
- `tomcat = 7.0.21`
- `tomcat = 7.0.22`
- `tomcat = 7.0.23`
- `tomcat = 7.0.25`
- `tomcat = 7.0.28`
- `tomcat = 7.0.30`
- `tomcat = 7.0.32`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
