The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script access to a cookie.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Tomcat | Apache | 6.0 (including) | 6.0 (including) |
Tomcat | Apache | 6.0.0 (including) | 6.0.0 (including) |
Tomcat | Apache | 6.0.1 (including) | 6.0.1 (including) |
Tomcat | Apache | 6.0.2 (including) | 6.0.2 (including) |
Tomcat | Apache | 6.0.3 (including) | 6.0.3 (including) |
Tomcat | Apache | 6.0.4 (including) | 6.0.4 (including) |
Tomcat | Apache | 6.0.5 (including) | 6.0.5 (including) |
Tomcat | Apache | 6.0.6 (including) | 6.0.6 (including) |
Tomcat | Apache | 6.0.7 (including) | 6.0.7 (including) |
Tomcat | Apache | 6.0.8 (including) | 6.0.8 (including) |
Tomcat | Apache | 6.0.9 (including) | 6.0.9 (including) |
Tomcat | Apache | 6.0.10 (including) | 6.0.10 (including) |
Tomcat | Apache | 6.0.11 (including) | 6.0.11 (including) |
Tomcat | Apache | 6.0.12 (including) | 6.0.12 (including) |
Tomcat | Apache | 6.0.13 (including) | 6.0.13 (including) |
Tomcat | Apache | 6.0.14 (including) | 6.0.14 (including) |
Tomcat | Apache | 6.0.15 (including) | 6.0.15 (including) |
Tomcat | Apache | 6.0.16 (including) | 6.0.16 (including) |
Tomcat | Apache | 6.0.17 (including) | 6.0.17 (including) |
Tomcat | Apache | 6.0.18 (including) | 6.0.18 (including) |
Tomcat | Apache | 6.0.19 (including) | 6.0.19 (including) |
Tomcat | Apache | 6.0.20 (including) | 6.0.20 (including) |
Tomcat | Apache | 6.0.24 (including) | 6.0.24 (including) |
Tomcat | Apache | 6.0.26 (including) | 6.0.26 (including) |
Tomcat | Apache | 6.0.27 (including) | 6.0.27 (including) |
Tomcat | Apache | 6.0.28 (including) | 6.0.28 (including) |
Tomcat | Apache | 6.0.29 (including) | 6.0.29 (including) |
Tomcat5 | Ubuntu | dapper | * |
Tomcat5.5 | Ubuntu | hardy | * |
Tomcat6 | Ubuntu | devel | * |
Tomcat6 | Ubuntu | karmic | * |
Tomcat6 | Ubuntu | lucid | * |
Tomcat6 | Ubuntu | maverick | * |