CVE-2007-3385
medium · 4.3Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 does not properly handle the \" character sequence in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks.
4.3
CVSS
16.9%
EPSS (exploit prob.)
97th
EPSS percentile
2007-08-14
Published
AV:N/AC:M/Au:N/C:P/I:N/A:N
Weaknesses
CWE-200
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | tomcat | 3.3 |
| apache | tomcat | 3.3.1 |
| apache | tomcat | 3.3.1a |
| apache | tomcat | 3.3.2 |
| apache | tomcat | 4.1.0 |
| apache | tomcat | 4.1.1 |
| apache | tomcat | 4.1.2 |
| apache | tomcat | 4.1.3 |
| apache | tomcat | 4.1.3 |
| apache | tomcat | 4.1.9 |
| apache | tomcat | 4.1.10 |
| apache | tomcat | 4.1.15 |
| apache | tomcat | 4.1.24 |
| apache | tomcat | 4.1.28 |
| apache | tomcat | 4.1.31 |
| apache | tomcat | 4.1.36 |
| apache | tomcat | 5.0.0 |
| apache | tomcat | 5.0.1 |
| apache | tomcat | 5.0.2 |
| apache | tomcat | 5.0.3 |
| apache | tomcat | 5.0.4 |
| apache | tomcat | 5.0.5 |
| apache | tomcat | 5.0.6 |
| apache | tomcat | 5.0.7 |
| apache | tomcat | 5.0.8 |
| apache | tomcat | 5.0.9 |
| apache | tomcat | 5.0.10 |
| apache | tomcat | 5.0.11 |
| apache | tomcat | 5.0.12 |
| apache | tomcat | 5.0.13 |
| apache | tomcat | 5.0.14 |
| apache | tomcat | 5.0.15 |
| apache | tomcat | 5.0.16 |
| apache | tomcat | 5.0.17 |
| apache | tomcat | 5.0.18 |
| apache | tomcat | 5.0.19 |
| apache | tomcat | 5.0.21 |
| apache | tomcat | 5.0.22 |
| apache | tomcat | 5.0.23 |
| apache | tomcat | 5.0.24 |
Check a specific version with /api/v1/cve/match.
References
- http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01192554
- http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html
- http://secunia.com/advisories/26466
- http://secunia.com/advisories/26898
- http://secunia.com/advisories/27037
- http://secunia.com/advisories/27267
- http://secunia.com/advisories/27727
- http://secunia.com/advisories/28317
- http://secunia.com/advisories/28361
- http://secunia.com/advisories/29242
- http://secunia.com/advisories/30802
- http://secunia.com/advisories/33668
- http://secunia.com/advisories/36486
- http://secunia.com/advisories/44183
- http://securityreason.com/securityalert/3011
- http://securitytracker.com/id?1018557
- http://support.apple.com/kb/HT2163
- http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197540
- http://tomcat.apache.org/security-6.html
- http://www-01.ibm.com/support/docview.wss?uid=swg1IZ55562
- http://www.debian.org/security/2008/dsa-1447
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2007-3385