CVE-2015-5346Cross-site Scripting in Apache Tomcat

CWE-79Cross-site Scripting13 documents9 sources
Severity
8.1HIGHNVD
EPSS
36.2%
top 2.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 25
Latest updateMay 14

Description

Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages1 packages

NVDapache/tomcat63 versions+62

Also affects: Debian Linux 7.0, 8.0, Ubuntu Linux 12.04, 14.04, 15.10, 16.04

🔴Vulnerability Details

4
OSV
Improper Neutralization of Input During Web Page Generation in Apache Tomcat2022-05-14
GHSA
Improper Neutralization of Input During Web Page Generation in Apache Tomcat2022-05-14
CVEList
CVE-2015-5346: Session fixation vulnerability in Apache Tomcat 72016-02-25
OSV
CVE-2015-5346: Session fixation vulnerability in Apache Tomcat 72016-02-24

📋Vendor Advisories

4
Ubuntu
Tomcat vulnerabilities2016-07-05
Red Hat
tomcat: Session fixation2016-02-22
Debian
CVE-2015-5346: tomcat9 - Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8....2015
Apache
Apache tomcat: CVE-2015-5346

💬Community

4
Bugzilla
CVE-2015-5351 CVE-2016-0714 CVE-2016-0706 CVE-2015-5345 CVE-2015-5346 CVE-2016-0763 CVE-2016-3092 tomcat: multiple security vulnerabilities [epel-6]2016-07-01
Bugzilla
CVE-2015-5346 tomcat: Session fixation2016-02-23
Bugzilla
CVE-2015-5174 CVE-2015-5351 CVE-2016-0714 CVE-2016-0706 CVE-2015-5345 CVE-2015-5346 CVE-2016-0763 tomcat: multiple security vulnerabilities [epel-6]2016-02-23
Bugzilla
CVE-2015-5174 CVE-2015-5351 CVE-2016-0714 CVE-2016-0706 CVE-2015-5345 CVE-2015-5346 CVE-2016-0763 tomcat: multiple security vulnerabilities [fedora-all]2016-02-23
CVE-2015-5346 — Cross-site Scripting in Apache Tomcat | cvebase