CVE-2013-2067

⚪ Do wiadomości

Błąd w FormAuthenticator w Apache Tomcat umożliwia atak sesji przez wstrzyknięcie żądania.

CVSS
6.8
EPSS
7.1%
Exploit
none
Vendor
apache
Opis źródłowy (NVD)

java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.8
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)7.1%
Opublikowano (NVD)2013-06-01 14:21:05 UTC
Ostatnia modyfikacja (NVD)2026-10-09 20:17:06 UTC
Referencje