← All CVEs

CVE-2015-5346

high · 8.1

Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.

8.1
CVSS
10.6%
EPSS (exploit prob.)
96th
EPSS percentile
2016-02-25
Published

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

VendorProductAffected versions
apachetomcat7.0.0
apachetomcat7.0.2
apachetomcat7.0.4
apachetomcat7.0.5
apachetomcat7.0.6
apachetomcat7.0.10
apachetomcat7.0.11
apachetomcat7.0.12
apachetomcat7.0.14
apachetomcat7.0.16
apachetomcat7.0.19
apachetomcat7.0.20
apachetomcat7.0.21
apachetomcat7.0.22
apachetomcat7.0.23
apachetomcat7.0.25
apachetomcat7.0.26
apachetomcat7.0.27
apachetomcat7.0.28
apachetomcat7.0.29
apachetomcat7.0.30
apachetomcat7.0.32
apachetomcat7.0.33
apachetomcat7.0.34
apachetomcat7.0.35
apachetomcat7.0.37
apachetomcat7.0.39
apachetomcat7.0.40
apachetomcat7.0.41
apachetomcat7.0.42
apachetomcat7.0.47
apachetomcat7.0.50
apachetomcat7.0.52
apachetomcat7.0.53
apachetomcat7.0.54
apachetomcat7.0.55
apachetomcat7.0.56
apachetomcat7.0.57
apachetomcat7.0.59
apachetomcat7.0.61

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2015-5346