CVE Database
/

CVE-2019-17563

Back to search

CVE-2019-17563

Published: Dec 23, 2019

Modified: Aug 5, 2024

PUBLISHED

Description

When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability.

VendorProductVersions

Apache Software Foundation

Apache Tomcat

affected
9.0.0.M1 to 9.0.29
affected
8.5.0 to 8.5.49
affected
7.0.0 to 7.0.98

References

DSA-4596
vendor-advisory
x_refsource_DEBIAN
openSUSE-SU-2020:0038
vendor-advisory
x_refsource_SUSE
USN-4251-1
vendor-advisory
x_refsource_UBUNTU
GLSA-202003-43
vendor-advisory
x_refsource_GENTOO
DSA-4680
vendor-advisory
x_refsource_DEBIAN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now