CVE-2007-5333
medium · 5Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double quote (") characters or (2) %5C (encoded backslash) sequences in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks. NOTE: this issue exists because of an incomplete fix for CVE-2007-3385.
5
CVSS
62.6%
EPSS (exploit prob.)
99th
EPSS percentile
2008-02-12
Published
AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
CWE-200
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | tomcat | >= 4.1.0, <= 4.1.36 |
| apache | tomcat | >= 5.5.0, <= 5.5.25 |
| apache | tomcat | >= 6.0.0, <= 6.0.14 |
Check a specific version with /api/v1/cve/match.
References
- http://jvn.jp/jp/JVN%2309470767/index.html
- http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.html
- http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html
- http://marc.info/?l=bugtraq&m=139344343412337&w=2
- http://secunia.com/advisories/28878
- http://secunia.com/advisories/28884
- http://secunia.com/advisories/28915
- http://secunia.com/advisories/29711
- http://secunia.com/advisories/30676
- http://secunia.com/advisories/30802
- http://secunia.com/advisories/32036
- http://secunia.com/advisories/32222
- http://secunia.com/advisories/33330
- http://secunia.com/advisories/37460
- http://secunia.com/advisories/44183
- http://secunia.com/advisories/57126
- http://security.gentoo.org/glsa/glsa-200804-10.xml
- http://securityreason.com/securityalert/3636
- http://support.apple.com/kb/HT2163
- http://support.apple.com/kb/HT3216
- http://tomcat.apache.org/security-4.html
- http://tomcat.apache.org/security-5.html
- http://tomcat.apache.org/security-6.html
- http://www-01.ibm.com/support/docview.wss?uid=swg24018932
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2007-5333