CVE Vulnerabilities

CVE-2010-4312

Published: Nov 26, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:P
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script access to a cookie.

Affected Software

NameVendorStart VersionEnd Version
TomcatApache6.0 (including)6.0 (including)
TomcatApache6.0.0 (including)6.0.0 (including)
TomcatApache6.0.1 (including)6.0.1 (including)
TomcatApache6.0.2 (including)6.0.2 (including)
TomcatApache6.0.3 (including)6.0.3 (including)
TomcatApache6.0.4 (including)6.0.4 (including)
TomcatApache6.0.5 (including)6.0.5 (including)
TomcatApache6.0.6 (including)6.0.6 (including)
TomcatApache6.0.7 (including)6.0.7 (including)
TomcatApache6.0.8 (including)6.0.8 (including)
TomcatApache6.0.9 (including)6.0.9 (including)
TomcatApache6.0.10 (including)6.0.10 (including)
TomcatApache6.0.11 (including)6.0.11 (including)
TomcatApache6.0.12 (including)6.0.12 (including)
TomcatApache6.0.13 (including)6.0.13 (including)
TomcatApache6.0.14 (including)6.0.14 (including)
TomcatApache6.0.15 (including)6.0.15 (including)
TomcatApache6.0.16 (including)6.0.16 (including)
TomcatApache6.0.17 (including)6.0.17 (including)
TomcatApache6.0.18 (including)6.0.18 (including)
TomcatApache6.0.19 (including)6.0.19 (including)
TomcatApache6.0.20 (including)6.0.20 (including)
TomcatApache6.0.24 (including)6.0.24 (including)
TomcatApache6.0.26 (including)6.0.26 (including)
TomcatApache6.0.27 (including)6.0.27 (including)
TomcatApache6.0.28 (including)6.0.28 (including)
TomcatApache6.0.29 (including)6.0.29 (including)
Tomcat5Ubuntudapper*
Tomcat5.5Ubuntuhardy*
Tomcat6Ubuntudevel*
Tomcat6Ubuntukarmic*
Tomcat6Ubuntulucid*
Tomcat6Ubuntumaverick*

References