CVE-2015-5346
Last modified
CVE-2015-5346 is a vulnerability of currently unknown severity. Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.. EPSS estimates a 10.57% chance of exploitation in the next 30 days.
Description
Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Apache | Tomcat | 7.0.0 | Beta |
| Apache | Tomcat | 7.0.2 | Beta |
| Apache | Tomcat | 7.0.4 | Beta |
| Apache | Tomcat | 7.0.5 | Beta |
| Apache | Tomcat | 7.0.6 | — |
| Apache | Tomcat | 7.0.10 | — |
| Apache | Tomcat | 7.0.11 | — |
| Apache | Tomcat | 7.0.12 | — |
| Apache | Tomcat | 7.0.14 | — |
| Apache | Tomcat | 7.0.16 | — |
| Apache | Tomcat | 7.0.19 | — |
| Apache | Tomcat | 7.0.20 | — |
| Apache | Tomcat | 7.0.21 | — |
| Apache | Tomcat | 7.0.22 | — |
| Apache | Tomcat | 7.0.23 | — |
| Apache | Tomcat | 7.0.25 | — |
| Apache | Tomcat | 7.0.26 | — |
| Apache | Tomcat | 7.0.27 | — |
| Apache | Tomcat | 7.0.28 | — |
| Apache | Tomcat | 7.0.29 | — |
| Apache | Tomcat | 7.0.30 | — |
| Apache | Tomcat | 7.0.32 | — |
| Apache | Tomcat | 7.0.33 | — |
| Apache | Tomcat | 7.0.34 | — |
| Apache | Tomcat | 7.0.35 | — |
| Apache | Tomcat | 7.0.37 | — |
| Apache | Tomcat | 7.0.39 | — |
| Apache | Tomcat | 7.0.40 | — |
| Apache | Tomcat | 7.0.41 | — |
| Apache | Tomcat | 7.0.42 | — |
| Apache | Tomcat | 7.0.47 | — |
| Apache | Tomcat | 7.0.50 | — |
| Apache | Tomcat | 7.0.52 | — |
| Apache | Tomcat | 7.0.53 | — |
| Apache | Tomcat | 7.0.54 | — |
| Apache | Tomcat | 7.0.55 | — |
| Apache | Tomcat | 7.0.56 | — |
| Apache | Tomcat | 7.0.57 | — |
| Apache | Tomcat | 7.0.59 | — |
| Apache | Tomcat | 7.0.61 | — |
| Apache | Tomcat | 7.0.62 | — |
| Apache | Tomcat | 7.0.63 | — |
| Apache | Tomcat | 7.0.64 | — |
| Apache | Tomcat | 7.0.65 | — |
| Apache | Tomcat | 8.0.0 | Rc1 |
| Apache | Tomcat | 8.0.1 | — |
| Apache | Tomcat | 8.0.3 | — |
| Apache | Tomcat | 8.0.11 | — |
| Apache | Tomcat | 8.0.12 | — |
| Apache | Tomcat | 8.0.14 | — |
Showing 50 of 69 affected configurations. See NVD for the full list.
References
- http://tomcat.apache.org/security-7.htmlVendor Advisory
- http://tomcat.apache.org/security-8.htmlVendor Advisory
- http://tomcat.apache.org/security-9.htmlVendor Advisory
- http://tomcat.apache.org/security-7.htmlVendor Advisory
- http://tomcat.apache.org/security-8.htmlVendor Advisory
- http://tomcat.apache.org/security-9.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-5346?
How severe is CVE-2015-5346?
How do I fix CVE-2015-5346?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-5340Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8…
- CVE-2015-5341mod_scorm in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8…
- CVE-2015-5342The choice module in Moodle through 2.6.11, 2.7.x before 2.7…
- CVE-2015-5343Integer overflow in util.c in mod_dav_svn in Apache Subversi…
- CVE-2015-5344The camel-xstream component in Apache Camel before 2.15.5 an…
- CVE-2015-5345The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x…
- CVE-2015-5347Cross-site scripting (XSS) vulnerability in the getWindowOpe…
- CVE-2015-5348Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and…
- CVE-2015-5349The CSV export in Apache LDAP Studio and Apache Directory St…
- CVE-2015-5350In Garden versions 0.22.0-0.329.0, a vulnerability has been …
- CVE-2015-5351The (1) Manager and (2) Host Manager applications in Apache …
- CVE-2015-5352The x11_open_helper function in channels.c in ssh in OpenSSH…
Are you affected by CVE-2015-5346?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
