Логотип exploitDog
bind:CVE-2015-5346
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2015-5346

Количество 10

Количество 10

ubuntu логотип

CVE-2015-5346

больше 9 лет назад

Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.

CVSS3: 8.1
EPSS: Средний
redhat логотип

CVE-2015-5346

больше 9 лет назад

Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.

CVSS3: 8.1
EPSS: Средний
nvd логотип

CVE-2015-5346

больше 9 лет назад

Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.

CVSS3: 8.1
EPSS: Средний
debian логотип

CVE-2015-5346

больше 9 лет назад

Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x ...

CVSS3: 8.1
EPSS: Средний
github логотип

GHSA-jrcp-c39h-r29x

около 3 лет назад

Improper Neutralization of Input During Web Page Generation in Apache Tomcat

CVSS3: 8.1
EPSS: Средний
fstec логотип

BDU:2016-00612

больше 9 лет назад

Уязвимость сервера приложений Apache Tomcat, позволяющая нарушителю получить доступ к веб-сессиям

CVSS2: 6.8
EPSS: Средний
oracle-oval логотип

ELSA-2016-2046

больше 8 лет назад

ELSA-2016-2046: tomcat security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2016:0865-1

около 9 лет назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:0822-1

больше 9 лет назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:0769-1

больше 9 лет назад

Security update for tomcat

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2015-5346

Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.

CVSS3: 8.1
19%
Средний
больше 9 лет назад
redhat логотип
CVE-2015-5346

Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.

CVSS3: 8.1
19%
Средний
больше 9 лет назад
nvd логотип
CVE-2015-5346

Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.

CVSS3: 8.1
19%
Средний
больше 9 лет назад
debian логотип
CVE-2015-5346

Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x ...

CVSS3: 8.1
19%
Средний
больше 9 лет назад
github логотип
GHSA-jrcp-c39h-r29x

Improper Neutralization of Input During Web Page Generation in Apache Tomcat

CVSS3: 8.1
19%
Средний
около 3 лет назад
fstec логотип
BDU:2016-00612

Уязвимость сервера приложений Apache Tomcat, позволяющая нарушителю получить доступ к веб-сессиям

CVSS2: 6.8
19%
Средний
больше 9 лет назад
oracle-oval логотип
ELSA-2016-2046

ELSA-2016-2046: tomcat security update (IMPORTANT)

больше 8 лет назад
suse-cvrf логотип
openSUSE-SU-2016:0865-1

Security update for tomcat

около 9 лет назад
suse-cvrf логотип
SUSE-SU-2016:0822-1

Security update for tomcat

больше 9 лет назад
suse-cvrf логотип
SUSE-SU-2016:0769-1

Security update for tomcat

больше 9 лет назад

Уязвимостей на страницу