SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-17563

When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack.

HIGH 7.5EPSS 10.7%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 10.7%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.

Description

When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
10.69% probability · 96th percentile
CISA KEV
Not listed
Weakness
CWE-384
Affected
apache/tomcat · debian/debian linux · opensuse/leap · canonical/ubuntu linux · oracle/agile engineering data management · oracle/hyperion infrastructure technology · oracle/instantis enterprisetrack · oracle/micros relate crm software · oracle/mysql enterprise monitor · oracle/retail order broker · oracle/transportation management
Source
security@apache.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.