CVE-2014-0033
Published Feb 26, 2014
Last updated a year ago
Overview
- Description
- org/apache/catalina/connector/CoyoteAdapter.java in Apache Tomcat 6.0.33 through 6.0.37 does not consider the disableURLRewriting setting when handling a session ID in a URL, which allows remote attackers to conduct session fixation attacks via a crafted URL.
- Source
- secalert@redhat.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-20
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:apache:tomcat:6.0.33:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "48E5E8C3-21AD-4230-B945-AB7DE66307B9" }, { "criteria": "cpe:2.3:a:apache:tomcat:6.0.34:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2949EC36-0056-43F0-93EC-681EAC22B112" }, { "criteria": "cpe:2.3:a:apache:tomcat:6.0.35:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4945C8C1-C71B-448B-9075-07C6C92599CF" }, { "criteria": "cpe:2.3:a:apache:tomcat:6.0.36:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ED4730B0-2E09-408B-AFD4-FE00F73700FD" }, { "criteria": "cpe:2.3:a:apache:tomcat:6.0.37:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B8DE8A8A-7643-4292-BCC1-758AE0940207" } ], "operator": "OR" } ] } ]