CVE-2014-0033
published 2014-02-26CVE-2014-0033: org/apache/catalina/connector/CoyoteAdapter.java in Apache Tomcat 6.0.33 through 6.0.37 does not consider the disableURLRewriting setting when handling a…
PriorityP425medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
9.89%
95.1th percentile
org/apache/catalina/connector/CoyoteAdapter.java in Apache Tomcat 6.0.33 through 6.0.37 does not consider the disableURLRewriting setting when handling a session ID in a URL, which allows remote attackers to conduct session fixation attacks via a crafted URL.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv4.3MEDIUM
vendor_ubuntu5.8MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2014-03-06·CVSS 5.8
CVE-2013-4286 [MEDIUM] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in Tomcat.
It was discovered that Tomcat incorrectly handled certain inconsistent
HTTP headers. A remote attacker could possibly use this flaw to conduct
request smuggling attacks. (CVE-2013-4286)
It was discovered that Tomcat incorrectly handled certain requests
submitted using chunked transfer encoding. A remote attacker could use this
flaw to cause the Tomcat server to stop responding, resulting in a denial
of service. (CVE-2013-4322)
It was discovered that Tomcat incorrectly applied the disableURLRewriting
setting when handling a session id in a URL. A remote attacker could
possibly use this flaw to conduct session fixation attacks. This issue
only applied to Ubuntu 12.04 LTS. (CVE-2014-0033)
It was discover
Red Hat
tomcat: session fixation still possible with disableURLRewriting enabled
vendor_redhat·2014-02-25·CVSS 4.3
CVE-2014-0033 [MEDIUM] CWE-384 tomcat: session fixation still possible with disableURLRewriting enabled
tomcat: session fixation still possible with disableURLRewriting enabled
org/apache/catalina/connector/CoyoteAdapter.java in Apache Tomcat 6.0.33 through 6.0.37 does not consider the disableURLRewriting setting when handling a session ID in a URL, which allows remote attackers to conduct session fixation attacks via a crafted URL.
It was found that previous fixes in Tomcat 6 to path parameter handling introduced a regression that caused Tomcat to not properly disable URL rewriting to track session IDs when the disableURLRewriting option was enabled. A man-in-the-middle attacker could potentially use this flaw to hijack a user's session.
Statement: This issue did not affect JBoss Web, as shipped with various Red Hat JBoss products.
The disableURLRewriting property was introduced in Apach
GHSA
Improper Input Validation in Apache Tomcat
ghsa·2022-05-14
CVE-2014-0033 [MEDIUM] CWE-20 Improper Input Validation in Apache Tomcat
Improper Input Validation in Apache Tomcat
org/apache/catalina/connector/CoyoteAdapter.java in Apache Tomcat 6.0.33 through 6.0.37 does not consider the disableURLRewriting setting when handling a session ID in a URL, which allows remote attackers to conduct session fixation attacks via a crafted URL.
OSV
Improper Input Validation in Apache Tomcat
osv·2022-05-14
CVE-2014-0033 [MEDIUM] Improper Input Validation in Apache Tomcat
Improper Input Validation in Apache Tomcat
org/apache/catalina/connector/CoyoteAdapter.java in Apache Tomcat 6.0.33 through 6.0.37 does not consider the disableURLRewriting setting when handling a session ID in a URL, which allows remote attackers to conduct session fixation attacks via a crafted URL.
OSV
CVE-2014-0033: org/apache/catalina/connector/CoyoteAdapter
osv·2014-02-26·CVSS 4.3
CVE-2014-0033 [MEDIUM] CVE-2014-0033: org/apache/catalina/connector/CoyoteAdapter
org/apache/catalina/connector/CoyoteAdapter.java in Apache Tomcat 6.0.33 through 6.0.37 does not consider the disableURLRewriting setting when handling a session ID in a URL, which allows remote attackers to conduct session fixation attacks via a crafted URL.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-7812 Red Hat Satellite, Spacewalk: XSS in system-group
bugzilla·2014-12-11·CVSS 3.5
CVE-2014-7812 [LOW] CVE-2014-7812 Red Hat Satellite, Spacewalk: XSS in system-group
CVE-2014-7812 Red Hat Satellite, Spacewalk: XSS in system-group
Mickaël Gallier reports:
There are several stored XSS vulnerabilities in various fields in Satellite
server, they can be exploited by using the REST API to send XML data
containing malformed data.
One of these is in the system-group handling. Please see CVE-014-7811 for
the other vulnerabilities.
Discussion:
Acknowledgement:
Red Hat would like to thank Mickaël Gallier for reporting this issue.
---
This issue has been addressed in the following products:
Red Hat Satellite Server v 5.7
Via RHSA-2015:0033 https://rhn.redhat.com/errata/RHSA-2015-0033.html
---
This issue has been addressed in the following products:
Red Hat Satellite Server v 5.7
Via RHSA-2015:0033 https://rhn.redhat.com/errata/RHSA-2015-0033.html
Bugzilla
CVE-2014-7811 Red Hat Satellite, Spacewalk: multiple XSS
bugzilla·2014-10-24·CVSS 3.5
CVE-2014-7811 [LOW] CVE-2014-7811 Red Hat Satellite, Spacewalk: multiple XSS
CVE-2014-7811 Red Hat Satellite, Spacewalk: multiple XSS
Mickaël Gallier reports:
There are several stored XSS vulnerabilities in various fields in Satellite
server, they can be exploited by using the REST API to send XML data
containing malformed data.
Discussion:
Created attachment 951111
SW-master/Sat5-latest patch
This patch applies to the latest Spacewalk and Satellite5 codebase. Sat5.6 patch is still in progress.
---
Created attachment 951859
Sat5.6 patch
This patch applies to the 5.6 branch of the Satellite codebase
---
Acknowledgement:
Red Hat would like to thank Mickaël Gallier for reporting this issue.
---
This issue has been addressed in the following products:
Red Hat Satellite Server v 5.7
Via RHSA-2015:0033 https://rhn.redhat.com/errata/RHSA-2015-0033.html
---
Bugzilla
CVE-2014-0033 tomcat: session fixation still possible with disableURLRewriting enabled
bugzilla·2014-02-25·CVSS 4.3
CVE-2014-0033 [MEDIUM] CVE-2014-0033 tomcat: session fixation still possible with disableURLRewriting enabled
CVE-2014-0033 tomcat: session fixation still possible with disableURLRewriting enabled
Previous fixes in Tomcat 6 [1] to path parameter handling introduced a regression that meant session IDs provided in the URL were considered even when disableURLRewriting was configured to true. Note that the session is only used for that single request.
This flaw only affects Tomcat 6.0.33 up to and including 6.0.37. Tomcat 6.0.39 corrects this issue [2].
[1] http://svn.apache.org/viewvc?view=revision&revision=r1149220
[2] http://svn.apache.org/viewvc?view=revision&revision=1558822
Discussion:
Statement:
This issue did not affect JBoss Web, as shipped with various Red Hat JBoss products.
The disableURLRewriting property was introduced in Apache Tomcat 6.0.30. All versions of Apache Tomcat prior
http://seclists.org/fulldisclosure/2014/Dec/23http://secunia.com/advisories/59036http://secunia.com/advisories/59722http://secunia.com/advisories/59873http://svn.apache.org/viewvc?view=revision&revision=1558822http://tomcat.apache.org/security-6.htmlhttp://www-01.ibm.com/support/docview.wss?uid=swg21675886http://www-01.ibm.com/support/docview.wss?uid=swg21677147http://www-01.ibm.com/support/docview.wss?uid=swg21678231http://www.debian.org/security/2016/dsa-3530http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/65769http://www.ubuntu.com/usn/USN-2130-1http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1069919https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b%40%3Cdev.tomcat.apache.org%3Ehttp://seclists.org/fulldisclosure/2014/Dec/23http://secunia.com/advisories/59036http://secunia.com/advisories/59722http://secunia.com/advisories/59873http://svn.apache.org/viewvc?view=revision&revision=1558822http://tomcat.apache.org/security-6.htmlhttp://www-01.ibm.com/support/docview.wss?uid=swg21675886http://www-01.ibm.com/support/docview.wss?uid=swg21677147http://www-01.ibm.com/support/docview.wss?uid=swg21678231http://www.debian.org/security/2016/dsa-3530http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/65769http://www.ubuntu.com/usn/USN-2130-1http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1069919https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b%40%3Cdev.tomcat.apache.org%3E
2014-02-26
Published