[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247974

 
 

909

 
 

194654

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2007-3382Date: (C)2007-08-14   (M)2023-12-22


Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 treats single quotes ("'") as delimiters in cookies, which might cause sensitive information such as session IDs to be leaked and allow remote attackers to conduct session hijacking attacks.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.3
Exploit Score: 8.6
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
SECTRACK-1018556
http://www.securityfocus.com/archive/1/476442/100/0/threaded
http://www.securityfocus.com/archive/1/476466/100/0/threaded
http://www.securityfocus.com/archive/1/500396/100/0/threaded
http://www.securityfocus.com/archive/1/500412/100/0/threaded
BID-25316
SECUNIA-26466
SECUNIA-26898
SECUNIA-27037
SECUNIA-27267
SECUNIA-27727
SECUNIA-28317
SECUNIA-28361
SECUNIA-29242
SECUNIA-30802
SECUNIA-33668
SECUNIA-36486
ADV-2007-2902
ADV-2007-3386
ADV-2007-3527
ADV-2008-1981
ADV-2009-0233
APPLE-SA-2008-06-30
DSA-1447
DSA-1453
FEDORA-2007-3456
IZ55562
MDKSA-2007:241
RHSA-2007:0871
RHSA-2007:0950
RHSA-2008:0195
RHSA-2008:0261
SSRT071447
SSRT071472
SUSE-SR:2008:005
SUSE-SR:2009:004
VU#993544
https://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3%40%3Cdev.tomcat.apache.org%3E
http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx
http://support.apple.com/kb/HT2163
http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197540
http://tomcat.apache.org/security-6.html
oval:org.mitre.oval:def:11269
tomcat-quotecookie-information-disclosure(36006)

CPE    85
cpe:/a:apache:tomcat:5.5.3
cpe:/a:apache:tomcat:5.0.12
cpe:/a:apache:tomcat:5.5.2
cpe:/a:apache:tomcat:5.0.13
...
CWE    1
CWE-200
OVAL    2
oval:org.mitre.oval:def:7988
oval:org.mitre.oval:def:7989

© SecPod Technologies