Количество 13
Количество 13

BDU:2020-01971
Уязвимость формы аутентификации сервера приложений Apache Tomcat, связанная с недостатком механизма фиксации сеанса, позволяющая нарушителю получить несанкционированный доступ к конфиденциальным данным, вызвать отказ в обслуживании и оказать воздействие на целостность данных

CVE-2019-17563
When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability.

CVE-2019-17563
When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability.

CVE-2019-17563
When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability.
CVE-2019-17563
When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, ...
GHSA-9xcj-c8cr-8c3c
In Apache Tomcat, when using FORM authentication there was a narrow window where an attacker could perform a session fixation attack
ELSA-2020-4004
ELSA-2020-4004: tomcat security and bug fix update (IMPORTANT)

openSUSE-SU-2020:0038-1
Security update for tomcat

SUSE-SU-2020:0226-1
Security update for tomcat

SUSE-SU-2020:0029-1
Security update for tomcat

SUSE-SU-2020:1498-1
Security update for tomcat

SUSE-SU-2020:1497-1
Security update for tomcat

SUSE-SU-2020:0632-1
Security update for tomcat
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | BDU:2020-01971 Уязвимость формы аутентификации сервера приложений Apache Tomcat, связанная с недостатком механизма фиксации сеанса, позволяющая нарушителю получить несанкционированный доступ к конфиденциальным данным, вызвать отказ в обслуживании и оказать воздействие на целостность данных | CVSS3: 9.8 | 3% Низкий | больше 5 лет назад |
![]() | CVE-2019-17563 When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability. | CVSS3: 7.5 | 3% Низкий | больше 5 лет назад |
![]() | CVE-2019-17563 When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability. | CVSS3: 7.5 | 3% Низкий | больше 5 лет назад |
![]() | CVE-2019-17563 When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability. | CVSS3: 7.5 | 3% Низкий | больше 5 лет назад |
CVE-2019-17563 When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, ... | CVSS3: 7.5 | 3% Низкий | больше 5 лет назад | |
GHSA-9xcj-c8cr-8c3c In Apache Tomcat, when using FORM authentication there was a narrow window where an attacker could perform a session fixation attack | CVSS3: 7.5 | 3% Низкий | больше 5 лет назад | |
ELSA-2020-4004 ELSA-2020-4004: tomcat security and bug fix update (IMPORTANT) | больше 4 лет назад | |||
![]() | openSUSE-SU-2020:0038-1 Security update for tomcat | больше 5 лет назад | ||
![]() | SUSE-SU-2020:0226-1 Security update for tomcat | больше 5 лет назад | ||
![]() | SUSE-SU-2020:0029-1 Security update for tomcat | больше 5 лет назад | ||
![]() | SUSE-SU-2020:1498-1 Security update for tomcat | около 5 лет назад | ||
![]() | SUSE-SU-2020:1497-1 Security update for tomcat | около 5 лет назад | ||
![]() | SUSE-SU-2020:0632-1 Security update for tomcat | больше 5 лет назад |
Уязвимостей на страницу