CVE-2013-2067
Last modified
CVE-2013-2067 is a vulnerability of currently unknown severity. java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.. EPSS estimates a 7.15% chance of exploitation in the next 30 days.
Description
java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Tomcat | 6.0.21 |
| Apache | Tomcat | 6.0.24 |
| Apache | Tomcat | 6.0.26 |
| Apache | Tomcat | 6.0.27 |
| Apache | Tomcat | 6.0.28 |
| Apache | Tomcat | 6.0.29 |
| Apache | Tomcat | 6.0.30 |
| Apache | Tomcat | 6.0.31 |
| Apache | Tomcat | 6.0.32 |
| Apache | Tomcat | 6.0.33 |
| Apache | Tomcat | 6.0.35 |
| Apache | Tomcat | 6.0.36 |
| Apache | Tomcat | 7.0.0 |
| Apache | Tomcat | 7.0.1 |
| Apache | Tomcat | 7.0.2 |
| Apache | Tomcat | 7.0.3 |
| Apache | Tomcat | 7.0.4 |
| Apache | Tomcat | 7.0.5 |
| Apache | Tomcat | 7.0.6 |
| Apache | Tomcat | 7.0.7 |
| Apache | Tomcat | 7.0.8 |
| Apache | Tomcat | 7.0.9 |
| Apache | Tomcat | 7.0.10 |
| Apache | Tomcat | 7.0.11 |
| Apache | Tomcat | 7.0.12 |
| Apache | Tomcat | 7.0.13 |
| Apache | Tomcat | 7.0.14 |
| Apache | Tomcat | 7.0.15 |
| Apache | Tomcat | 7.0.16 |
| Apache | Tomcat | 7.0.17 |
| Apache | Tomcat | 7.0.18 |
| Apache | Tomcat | 7.0.19 |
| Apache | Tomcat | 7.0.20 |
| Apache | Tomcat | 7.0.21 |
| Apache | Tomcat | 7.0.22 |
| Apache | Tomcat | 7.0.23 |
| Apache | Tomcat | 7.0.25 |
| Apache | Tomcat | 7.0.28 |
| Apache | Tomcat | 7.0.30 |
| Apache | Tomcat | 7.0.32 |
References
- http://tomcat.apache.org/security-6.htmlVendor Advisory
- http://tomcat.apache.org/security-7.htmlVendor Advisory
- http://tomcat.apache.org/security-6.htmlVendor Advisory
- http://tomcat.apache.org/security-7.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-2067?
How severe is CVE-2013-2067?
How do I fix CVE-2013-2067?
Are you affected by CVE-2013-2067?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
