CVE Database
/

CVE-2014-0033

Back to search

CVE-2014-0033

Published: Feb 26, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

org/apache/catalina/connector/CoyoteAdapter.java in Apache Tomcat 6.0.33 through 6.0.37 does not consider the disableURLRewriting setting when handling a session ID in a URL, which allows remote attackers to conduct session fixation attacks via a crafted URL.

VendorProductVersions

n/a

n/a

affected
n/a

References

65769
vdb-entry
x_refsource_BID
DSA-3530
vendor-advisory
x_refsource_DEBIAN
59722
third-party-advisory
x_refsource_SECUNIA
USN-2130-1
vendor-advisory
x_refsource_UBUNTU
59873
third-party-advisory
x_refsource_SECUNIA
59036
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2014-0033 - Security Vulnerability | QwikSec