Beveiligingsadvies

CVE-2007-3385

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2007-08-14 22:00:00
Laatst bijgewerkt 2024-08-07 14:14:12
Toegewezen door redhat
CVSS-score geen score
Status PUBLISHED

Beschrijving

Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 does not properly handle the \" character sequence in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks.