Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2010-4312

Опубликовано: 26 нояб. 2010
Источник: debian
EPSS Низкий

Описание

The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script access to a cookie.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tomcat6fixed6.0.35-5package
tomcat6not-affectedlennypackage

EPSS

Процентиль: 80%
0.02136
Низкий

Связанные уязвимости

ubuntu
больше 15 лет назад

The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script access to a cookie.

redhat
больше 15 лет назад

The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script access to a cookie.

nvd
больше 15 лет назад

The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script access to a cookie.

github
около 4 лет назад

Apache Tomcat has cookies without HTTPOnly flag in Set-Cookie header

EPSS

Процентиль: 80%
0.02136
Низкий