Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2010-4312

Опубликовано: 26 нояб. 2010
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 6.4

Описание

The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script access to a cookie.

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

hardy

DNE

karmic

DNE

lucid

DNE

maverick

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

ignored

end of life
karmic

DNE

lucid

DNE

maverick

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

ignored

configuration issue
hardy

DNE

karmic

ignored

end of life
lucid

ignored

end of life
maverick

ignored

end of life
upstream

needs-triage

Показывать по

EPSS

Процентиль: 82%
0.01735
Низкий

6.4 Medium

CVSS2

Связанные уязвимости

redhat
больше 14 лет назад

The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script access to a cookie.

nvd
больше 14 лет назад

The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script access to a cookie.

debian
больше 14 лет назад

The default configuration of Apache Tomcat 6.x does not include the HT ...

github
около 3 лет назад

Apache Tomcat has cookies without HTTPOnly flag in Set-Cookie header

EPSS

Процентиль: 82%
0.01735
Низкий

6.4 Medium

CVSS2