← All CVEs

CVE-2019-17563

high · 7.5

When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability.

7.5
CVSS
10.7%
EPSS (exploit prob.)
96th
EPSS percentile
2019-12-23
Published

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-384

Affected products

VendorProductAffected versions
apachetomcat>= 7.0.0, <= 7.0.98
apachetomcat>= 8.5.0, <= 8.5.49
apachetomcat>= 9.0.0, <= 9.0.29
debiandebian_linux8.0
debiandebian_linux9.0
debiandebian_linux10.0
opensuseleap15.1
canonicalubuntu_linux16.04
oracleagile_engineering_data_management6.2.1.0
oraclehyperion_infrastructure_technology11.1.2.4
oracleinstantis_enterprisetrack>= 17.1, <= 17.3
oraclemicros_relate_crm_software11.4
oraclemysql_enterprise_monitor<= 4.0.11.5331
oraclemysql_enterprise_monitor>= 8.0.0, <= 8.0.18.1217
oracleretail_order_broker15.0
oracletransportation_management6.3.7

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-17563