Логотип exploitDog
bind:CVE-2015-5346
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2015-5346

Количество 10

Количество 10

ubuntu логотип

CVE-2015-5346

почти 10 лет назад

Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.

CVSS3: 8.1
EPSS: Средний
redhat логотип

CVE-2015-5346

почти 10 лет назад

Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.

CVSS3: 8.1
EPSS: Средний
nvd логотип

CVE-2015-5346

почти 10 лет назад

Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.

CVSS3: 8.1
EPSS: Средний
debian логотип

CVE-2015-5346

почти 10 лет назад

Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x ...

CVSS3: 8.1
EPSS: Средний
github логотип

GHSA-jrcp-c39h-r29x

больше 3 лет назад

Improper Neutralization of Input During Web Page Generation in Apache Tomcat

CVSS3: 8.1
EPSS: Средний
fstec логотип

BDU:2016-00612

почти 10 лет назад

Уязвимость сервера приложений Apache Tomcat, позволяющая нарушителю получить доступ к веб-сессиям

CVSS2: 6.8
EPSS: Средний
oracle-oval логотип

ELSA-2016-2046

больше 9 лет назад

ELSA-2016-2046: tomcat security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2016:0865-1

почти 10 лет назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:0822-1

почти 10 лет назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:0769-1

почти 10 лет назад

Security update for tomcat

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2015-5346

Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.

CVSS3: 8.1
36%
Средний
почти 10 лет назад
redhat логотип
CVE-2015-5346

Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.

CVSS3: 8.1
36%
Средний
почти 10 лет назад
nvd логотип
CVE-2015-5346

Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.

CVSS3: 8.1
36%
Средний
почти 10 лет назад
debian логотип
CVE-2015-5346

Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x ...

CVSS3: 8.1
36%
Средний
почти 10 лет назад
github логотип
GHSA-jrcp-c39h-r29x

Improper Neutralization of Input During Web Page Generation in Apache Tomcat

CVSS3: 8.1
36%
Средний
больше 3 лет назад
fstec логотип
BDU:2016-00612

Уязвимость сервера приложений Apache Tomcat, позволяющая нарушителю получить доступ к веб-сессиям

CVSS2: 6.8
36%
Средний
почти 10 лет назад
oracle-oval логотип
ELSA-2016-2046

ELSA-2016-2046: tomcat security update (IMPORTANT)

больше 9 лет назад
suse-cvrf логотип
openSUSE-SU-2016:0865-1

Security update for tomcat

почти 10 лет назад
suse-cvrf логотип
SUSE-SU-2016:0822-1

Security update for tomcat

почти 10 лет назад
suse-cvrf логотип
SUSE-SU-2016:0769-1

Security update for tomcat

почти 10 лет назад

Уязвимостей на страницу