CVE Vulnerabilities

CVE-2015-5346

Published: Feb 25, 2016 | Modified: Apr 12, 2025
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
6.8 LOW
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
8.1 LOW
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.

Affected Software

NameVendorStart VersionEnd Version
TomcatApache7.0.0-beta (including)7.0.0-beta (including)
TomcatApache7.0.2-beta (including)7.0.2-beta (including)
TomcatApache7.0.4-beta (including)7.0.4-beta (including)
TomcatApache7.0.5-beta (including)7.0.5-beta (including)
TomcatApache7.0.6 (including)7.0.6 (including)
TomcatApache7.0.10 (including)7.0.10 (including)
TomcatApache7.0.11 (including)7.0.11 (including)
TomcatApache7.0.12 (including)7.0.12 (including)
TomcatApache7.0.14 (including)7.0.14 (including)
TomcatApache7.0.16 (including)7.0.16 (including)
TomcatApache7.0.19 (including)7.0.19 (including)
TomcatApache7.0.20 (including)7.0.20 (including)
TomcatApache7.0.21 (including)7.0.21 (including)
TomcatApache7.0.22 (including)7.0.22 (including)
TomcatApache7.0.23 (including)7.0.23 (including)
TomcatApache7.0.25 (including)7.0.25 (including)
TomcatApache7.0.26 (including)7.0.26 (including)
TomcatApache7.0.27 (including)7.0.27 (including)
TomcatApache7.0.28 (including)7.0.28 (including)
TomcatApache7.0.29 (including)7.0.29 (including)
TomcatApache7.0.30 (including)7.0.30 (including)
TomcatApache7.0.32 (including)7.0.32 (including)
TomcatApache7.0.33 (including)7.0.33 (including)
TomcatApache7.0.34 (including)7.0.34 (including)
TomcatApache7.0.35 (including)7.0.35 (including)
TomcatApache7.0.37 (including)7.0.37 (including)
TomcatApache7.0.39 (including)7.0.39 (including)
TomcatApache7.0.40 (including)7.0.40 (including)
TomcatApache7.0.41 (including)7.0.41 (including)
TomcatApache7.0.42 (including)7.0.42 (including)
TomcatApache7.0.47 (including)7.0.47 (including)
TomcatApache7.0.50 (including)7.0.50 (including)
TomcatApache7.0.52 (including)7.0.52 (including)
TomcatApache7.0.53 (including)7.0.53 (including)
TomcatApache7.0.54 (including)7.0.54 (including)
TomcatApache7.0.55 (including)7.0.55 (including)
TomcatApache7.0.56 (including)7.0.56 (including)
TomcatApache7.0.57 (including)7.0.57 (including)
TomcatApache7.0.59 (including)7.0.59 (including)
TomcatApache7.0.61 (including)7.0.61 (including)
TomcatApache7.0.62 (including)7.0.62 (including)
TomcatApache7.0.63 (including)7.0.63 (including)
TomcatApache7.0.64 (including)7.0.64 (including)
TomcatApache7.0.65 (including)7.0.65 (including)
TomcatApache8.0.0-rc1 (including)8.0.0-rc1 (including)
TomcatApache8.0.0-rc10 (including)8.0.0-rc10 (including)
TomcatApache8.0.0-rc3 (including)8.0.0-rc3 (including)
TomcatApache8.0.0-rc5 (including)8.0.0-rc5 (including)
TomcatApache8.0.1 (including)8.0.1 (including)
TomcatApache8.0.3 (including)8.0.3 (including)
TomcatApache8.0.11 (including)8.0.11 (including)
TomcatApache8.0.12 (including)8.0.12 (including)
TomcatApache8.0.14 (including)8.0.14 (including)
TomcatApache8.0.15 (including)8.0.15 (including)
TomcatApache8.0.17 (including)8.0.17 (including)
TomcatApache8.0.18 (including)8.0.18 (including)
TomcatApache8.0.20 (including)8.0.20 (including)
TomcatApache8.0.21 (including)8.0.21 (including)
TomcatApache8.0.22 (including)8.0.22 (including)
TomcatApache8.0.23 (including)8.0.23 (including)
TomcatApache8.0.24 (including)8.0.24 (including)
TomcatApache8.0.26 (including)8.0.26 (including)
TomcatApache8.0.27 (including)8.0.27 (including)
TomcatApache8.0.28 (including)8.0.28 (including)
TomcatApache8.0.29 (including)8.0.29 (including)
TomcatApache9.0.0-milestone1 (including)9.0.0-milestone1 (including)
Red Hat Enterprise Linux 7RedHattomcat-0:7.0.54-8.el7_2*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHattomcat7-0:7.0.54-23_patch_05.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 7RedHattomcat7-0:7.0.54-23_patch_05.ep6.el7*
Red Hat JBoss Web Server 2.1RedHattomcat7*
Red Hat JBoss Web Server 3.0RedHattomcat7*
Red Hat JBoss Web Server 3.0RedHattomcat8*
Red Hat JBoss Web Server 3 for RHEL 6RedHathttpd24-0:2.4.6-61.ep7.el6*
Red Hat JBoss Web Server 3 for RHEL 6RedHatmod_security-jws3-0:2.8.0-7.GA.ep7.el6*
Red Hat JBoss Web Server 3 for RHEL 6RedHattomcat7-0:7.0.59-50_patch_01.ep7.el6*
Red Hat JBoss Web Server 3 for RHEL 6RedHattomcat8-0:8.0.18-61_patch_01.ep7.el6*
Red Hat JBoss Web Server 3 for RHEL 7RedHathttpd24-0:2.4.6-61.ep7.el7*
Red Hat JBoss Web Server 3 for RHEL 7RedHatmod_security-jws3-0:2.8.0-7.GA.ep7.el7*
Red Hat JBoss Web Server 3 for RHEL 7RedHattomcat7-0:7.0.59-50_patch_01.ep7.el7*
Red Hat JBoss Web Server 3 for RHEL 7RedHattomcat8-0:8.0.18-61_patch_01.ep7.el7*
Tomcat7Ubuntuesm-infra-legacy/trusty*
Tomcat7Ubuntuprecise*
Tomcat7Ubuntutrusty*
Tomcat7Ubuntutrusty/esm*
Tomcat7Ubuntuupstream*
Tomcat7Ubuntuwily*
Tomcat8Ubuntuupstream*
Tomcat8Ubuntuwily*

References