SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-2067

java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions,…

MEDIUM 6.8EPSS 7.15%

Does this matter?

Lower severity and a low EPSS score (7.15%). Track it; it rarely justifies an emergency change on its own.

Description

java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
7.15% probability · 94th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
apache/tomcat
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.