ZeroHour

CVE-2019-17563

CVSS 3.1
7.5 high
EPSS
11%p96
Published
()
Modified
Description

When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability.

Vendors
apachedebianopensusecanonicaloracle
Products
tomcat, debian linux, leap, ubuntu linux, agile engineering data management, hyperion infrastructure technology, instantis enterprisetrack, micros relate crm software, mysql enterprise monitor, retail order broker, transportation management
Weakness
CWE-384
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.