|
|
Log in / Subscribe / Register

tomcat: session hijacking

Package(s):tomcat CVE #(s):CVE-2015-5346
Created:March 3, 2016 Updated:March 9, 2016
Description: From the Mageia advisory:

Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java (CVE-2015-5346).

Alerts:
Scientific Linux SLSA-2016:2046-1 tomcat 2016-10-11
CentOS CESA-2016:2046 tomcat 2016-10-11
Oracle ELSA-2016-2046 tomcat 2016-10-10
Red Hat RHSA-2016:2046-01 tomcat 2016-10-10
Ubuntu USN-3024-1 tomcat6, tomcat7 2016-07-05
Debian DSA-3609-1 tomcat8 2016-06-29
Debian DSA-3552-1 tomcat7 2016-04-17
Debian DSA-3530-1 tomcat6 2016-03-25
openSUSE openSUSE-SU-2016:0865-1 tomcat 2016-03-23
SUSE SUSE-SU-2016:0822-1 tomcat 2016-03-18
SUSE SUSE-SU-2016:0769-1 tomcat 2016-03-15
Mageia MGASA-2016-0090 tomcat 2016-03-02

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds