Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-55668

Опубликовано: 13 авг. 2025
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.

A session fixation vulnerability has been identified in Apache Tomcat, affecting its rewrite functionality. If the rewrite valve is enabled for a web application, an attacker can craft a specific URL. If a victim clicks on this malicious URL, their subsequent interaction with the resource will occur within the context of the attacker's session. This could allow an attacker to hijack the victim's session and perform actions on their behalf.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Certificate System 10redhat-pki:10/jssFix deferred
Red Hat Certificate System 10redhat-pki:10/redhat-pkiFix deferred
Red Hat Data Grid 8tomcat-catalinaFix deferred
Red Hat Enterprise Linux 10dogtag-pkiFix deferred
Red Hat Enterprise Linux 10jssFix deferred
Red Hat Enterprise Linux 10mod_proxy_clusterFix deferred
Red Hat Enterprise Linux 8log4j:2/log4jFix deferred
Red Hat Enterprise Linux 9jssFix deferred
Red Hat Enterprise Linux 9log4jFix deferred
Red Hat Enterprise Linux 9mod_proxy_clusterFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-384
https://bugzilla.redhat.com/show_bug.cgi?id=2388226org.apache.tomcat/tomcat-catalina: Apache Tomcat: session fixation via rewrite valve

EPSS

Процентиль: 1%
0.00012
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
13 дней назад

Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.

CVSS3: 6.5
nvd
15 дней назад

Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.

CVSS3: 6.5
debian
15 дней назад

Session Fixation vulnerability in Apache Tomcat via rewrite valve. Th ...

CVSS3: 6.5
github
15 дней назад

Apache Tomcat Session Fixation vulnerability

CVSS3: 6.5
fstec
3 месяца назад

Уязвимость сервера приложений Apache Tomcat, связанная с недостатками разграничения доступа, позволяющая нарушителю перехватить сеанс и получить доступ к учетной записи пользователя

EPSS

Процентиль: 1%
0.00012
Низкий

6.5 Medium

CVSS3