CVE-2019-17563
published 2019-12-23CVE-2019-17563: When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could…
PriorityP352high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
EPSS
10.69%
95.3th percentile
When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | 7.0.0 – 7.0.98 | — |
| apache | tomcat | 8.5.0 – 8.5.49 | — |
| apache | tomcat | 9.0.0 – 9.0.29 | — |
| apache_software_foundation | apache_tomcat | — | — |
| apache_software_foundation | apache_tomcat | — | — |
| apache_software_foundation | apache_tomcat | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | tomcat9 | < tomcat9 9.0.31-1 (bookworm) | tomcat9 9.0.31-1 (bookworm) |
| opensuse | leap | — | — |
| oracle | agile_engineering_data_management | — | — |
| oracle | hyperion_infrastructure_technology | — | — |
| oracle | instantis_enterprisetrack | 17.1 – 17.3 | — |
| oracle | micros_relate_crm_software | — | — |
| oracle | mysql_enterprise_monitor | <= 4.0.11.5331 | — |
| oracle | mysql_enterprise_monitor | 8.0.0 – 8.0.18.1217 | — |
| oracle | retail_order_broker | — | — |
| oracle | transportation_management | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_oracle9.8HIGH
vendor_apache7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Hyperion Risk Matrix: Common Security (Apache Tomcat) — CVE-2019-17563
vendor_oracle·2021-01-15·CVSS 7.5
CVE-2019-17563 [HIGH] Oracle Oracle Hyperion Risk Matrix: Common Security (Apache Tomcat) — CVE-2019-17563
Oracle Oracle Hyperion Risk Matrix: Common Security (Apache Tomcat) vulnerability
CVE: CVE-2019-17563
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Oracle
Oracle Oracle Supply Chain Risk Matrix: Install (Apache Tomcat) — CVE-2019-17563
vendor_oracle·2020-07-15·CVSS 9.8
CVE-2019-17563 [HIGH] Oracle Oracle Supply Chain Risk Matrix: Install (Apache Tomcat) — CVE-2019-17563
Oracle Oracle Supply Chain Risk Matrix: Install (Apache Tomcat) vulnerability
CVE: CVE-2019-17563
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
Oracle
Oracle Oracle Database Server Risk Matrix: WLM (Apache Tomcat) — CVE-2019-17563
vendor_oracle·2020-04-15·CVSS 7.5
CVE-2019-17563 [HIGH] Oracle Oracle Database Server Risk Matrix: WLM (Apache Tomcat) — CVE-2019-17563
Oracle Oracle Database Server Risk Matrix: WLM (Apache Tomcat) vulnerability
CVE: CVE-2019-17563
CVSS: 7.5
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2020-01-27·CVSS 7.0
CVE-2019-12418 [HIGH] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in Tomcat.
It was discovered that Tomcat incorrectly handled the RMI registry when
configured with the JMX Remote Lifecycle Listener. A local attacker could
possibly use this issue to obtain credentials and gain complete control
over the Tomcat instance. (CVE-2019-12418)
It was discovered that Tomcat incorrectly handled FORM authentication. A
remote attacker could possibly use this issue to perform a session fixation
attack. (CVE-2019-17563)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
tomcat: Session fixation when using FORM authentication
vendor_redhat·2019-12-18·CVSS 7.5
CVE-2019-17563 [HIGH] CWE-384 tomcat: Session fixation when using FORM authentication
tomcat: Session fixation when using FORM authentication
When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability.
It was found that tomcat's FORM authentication allowed a very small period in which an attacker could possibly force a victim to use a valid user session, or Session Fixation. While practical exploit of this issue is deemed highly improbable, an abundance of caution merits it be considered a flaw. The highest threat from this vulnerability is to system availability, but also threatens da
Debian
CVE-2019-17563: tomcat9 - When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8...
vendor_debian·2019·CVSS 7.5
CVE-2019-17563 [HIGH] CVE-2019-17563: tomcat9 - When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8...
When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability.
Scope: local
bookworm: resolved (fixed in 9.0.31-1)
bullseye: resolved (fixed in 9.0.31-1)
forky: resolved (fixed in 9.0.31-1)
sid: resolved (fixed in 9.0.31-1)
trixie: resolved (fixed in 9.0.31-1)
Apache
Apache tomcat: CVE-2019-17563
vendor_apache·CVSS 7.5
CVE-2019-17563 [HIGH] Apache tomcat: CVE-2019-17563
Apache tomcat: CVE-2019-17563
When using FORM authentication there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability. This was fixed with commit e19a202e . This issue was reported to the Apache Tomcat Security Team by William Marlow (IBM) on 19 November 2019. The issue was made public on 18 December 2019. Affects: 8.5.0 to 8.5.49 21 November 2019 Fixed in Apache Tomcat 8.5.49 Note: The issue below was fixed in Apache Tomcat 8.0.48 but the release vote for the 8.0.48 release candidate did not pass. Therefore, although users must download 8.0.49 to obtain a version that includes the fix for this issue, ver
OSV
tomcat8 vulnerabilities
osv·2020-01-27·CVSS 7.0
CVE-2019-12418 [HIGH] tomcat8 vulnerabilities
tomcat8 vulnerabilities
It was discovered that Tomcat incorrectly handled the RMI registry when
configured with the JMX Remote Lifecycle Listener. A local attacker could
possibly use this issue to obtain credentials and gain complete control
over the Tomcat instance. (CVE-2019-12418)
It was discovered that Tomcat incorrectly handled FORM authentication. A
remote attacker could possibly use this issue to perform a session fixation
attack. (CVE-2019-17563)
GHSA
In Apache Tomcat, when using FORM authentication there was a narrow window where an attacker could perform a session fixation attack
ghsa·2019-12-26
CVE-2019-17563 [HIGH] CWE-384 In Apache Tomcat, when using FORM authentication there was a narrow window where an attacker could perform a session fixation attack
In Apache Tomcat, when using FORM authentication there was a narrow window where an attacker could perform a session fixation attack
When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability.
OSV
In Apache Tomcat, when using FORM authentication there was a narrow window where an attacker could perform a session fixation attack
osv·2019-12-26
CVE-2019-17563 [HIGH] In Apache Tomcat, when using FORM authentication there was a narrow window where an attacker could perform a session fixation attack
In Apache Tomcat, when using FORM authentication there was a narrow window where an attacker could perform a session fixation attack
When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability.
OSV
CVE-2019-17563: When using FORM authentication with Apache Tomcat 9
osv·2019-12-23·CVSS 7.5
CVE-2019-17563 [HIGH] CVE-2019-17563: When using FORM authentication with Apache Tomcat 9
When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability.
No detection rules found.
No public exploits indexed.
HackerOne
Tomcat examples available for public, Disclosure Apache Tomcat version, Critical/High/Medium CVE
hackerone·2020-06-11·CVSS 4.3
[MEDIUM] Tomcat examples available for public, Disclosure Apache Tomcat version, Critical/High/Medium CVE
Tomcat examples available for public, Disclosure Apache Tomcat version, Critical/High/Medium CVE
**Summary:**
There are multiple issues found on ███:
1. ███████/examples/ - Apache Tomcat examples are available for public. Multiple issues - session and cookies manipulation, internals IP disclosure.
2. Error page contains information about Apache Tomcat version
3. Reported Tomcat version is vulnerable. Multiple CVEs - critical, high and medium
**Description:**
1. Examples are available by link: ███████/examples/
2. Information disclosure about Apache Tomcat version
3. Vulnerable version Apache Tomcat/8.5.33
https://nvd.nist.gov/vuln/detail/CVE-2020-1938
Base Score: 9.8 CRITICALVector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
https://nvd.nist.gov/vuln/detail/CVE-2019-0232
Base Score
Bugzilla
CVE-2019-17563 tomcat: session fixation when using FORM authentication [epel-all]
bugzilla·2019-12-20·CVSS 7.5
CVE-2019-17563 [HIGH] CVE-2019-17563 tomcat: session fixation when using FORM authentication [epel-all]
CVE-2019-17563 tomcat: session fixation when using FORM authentication [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versio
Bugzilla
CVE-2019-17563 tomcat: session fixation when using FORM authentication [fedora-all]
bugzilla·2019-12-20·CVSS 7.5
CVE-2019-17563 [HIGH] CVE-2019-17563 tomcat: session fixation when using FORM authentication [fedora-all]
CVE-2019-17563 tomcat: session fixation when using FORM authentication [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ve
Bugzilla
CVE-2019-17563 tomcat: Session fixation when using FORM authentication
bugzilla·2019-12-20·CVSS 7.5
CVE-2019-17563 [HIGH] CVE-2019-17563 tomcat: Session fixation when using FORM authentication
CVE-2019-17563 tomcat: Session fixation when using FORM authentication
When using FORM authentication there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability.
Reference:
https://tomcat.apache.org/security-7.html
https://tomcat.apache.org/security-8.html
http://tomcat.apache.org/security-9.html
Upstream commits:
https://github.com/apache/tomcat/commit/ab72a10
https://github.com/apache/tomcat/commit/e19a202
https://github.com/apache/tomcat/commit/1ecba14
Discussion:
Created tomcat tracking bugs for this issue:
Affects: epel-all [bug 1785712]
Affects: fedora-all [bug 1785713]
---
External References
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00013.htmlhttps://lists.apache.org/thread.html/8b4c1db8300117b28a0f3f743c0b9e3f964687a690cdf9662a884bbd%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/reb9a66f176df29b9a832caa95ebd9ffa3284e8f4922ec4fa3ad8eb2e%40%3Cissues.cxf.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/01/msg00024.htmlhttps://lists.debian.org/debian-lts-announce/2020/05/msg00026.htmlhttps://seclists.org/bugtraq/2019/Dec/43https://security.gentoo.org/glsa/202003-43https://security.netapp.com/advisory/ntap-20200107-0001/https://usn.ubuntu.com/4251-1/https://www.debian.org/security/2019/dsa-4596https://www.debian.org/security/2020/dsa-4680https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-01/msg00013.htmlhttps://lists.apache.org/thread.html/8b4c1db8300117b28a0f3f743c0b9e3f964687a690cdf9662a884bbd%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/reb9a66f176df29b9a832caa95ebd9ffa3284e8f4922ec4fa3ad8eb2e%40%3Cissues.cxf.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/01/msg00024.htmlhttps://lists.debian.org/debian-lts-announce/2020/05/msg00026.htmlhttps://seclists.org/bugtraq/2019/Dec/43https://security.gentoo.org/glsa/202003-43https://security.netapp.com/advisory/ntap-20200107-0001/https://usn.ubuntu.com/4251-1/https://www.debian.org/security/2019/dsa-4596https://www.debian.org/security/2020/dsa-4680https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.html
2019-12-23
Published