Описание
The org.apache.catalina.connector.Response.encodeURL method in Red Hat JBoss Web 7.1.x and earlier, when the tracking mode is set to COOKIE, sends the jsessionid in the URL of the first response of a session, which allows remote attackers to obtain the session id (1) via a man-in-the-middle attack or (2) by reading a log.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | tomcat5 | Not affected | ||
| Red Hat Enterprise Linux 6 | tomcat6 | Not affected | ||
| Red Hat JBoss BRMS 5 | jbossweb | Not affected | ||
| Red Hat JBoss Enterprise Web Server 1 | tomcat5 | Not affected | ||
| Red Hat JBoss Enterprise Web Server 1 | tomcat6 | Not affected | ||
| Red Hat JBoss Portal 5 | jbossweb | Not affected | ||
| Red Hat JBoss Portal 6 | jbossweb | Affected | ||
| Red Hat JBoss SOA Platform 5 | jbossweb | Not affected | ||
| Red Hat JBoss Enterprise Application Platform 6.1 | Fixed | RHSA-2013:0833 | 20.05.2013 | |
| Red Hat JBoss Enterprise Application Platform 6 for RHEL 5 | apache-commons-daemon-eap6 | Fixed | RHSA-2013:0839 | 20.05.2013 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
The org.apache.catalina.connector.Response.encodeURL method in Red Hat JBoss Web 7.1.x and earlier, when the tracking mode is set to COOKIE, sends the jsessionid in the URL of the first response of a session, which allows remote attackers to obtain the session id (1) via a man-in-the-middle attack or (2) by reading a log.
The org.apache.catalina.connector.Response.encodeURL method in Red Hat JBoss Web 7.1.x and earlier, when the tracking mode is set to COOKIE, sends the jsessionid in the URL of the first response of a session, which allows remote attackers to obtain the session id (1) via a man-in-the-middle attack or (2) by reading a log.
The org.apache.catalina.connector.Response.encodeURL method in Red Hat ...
The org.apache.catalina.connector.Response.encodeURL method in Red Hat JBoss Web 7.1.x and earlier, when the tracking mode is set to COOKIE, sends the jsessionid in the URL of the first response of a session, which allows remote attackers to obtain the session id (1) via a man-in-the-middle attack or (2) by reading a log.
EPSS
4.3 Medium
CVSS2