First published: Tue Aug 14 2007(Updated: )
Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 treats single quotes ("'") as delimiters in cookies, which might cause sensitive information such as session IDs to be leaked and allow remote attackers to conduct session hijacking attacks.
Credit: secalert@redhat.com secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.apache.tomcat:tomcat | >=3.3.0<=3.3.2 | |
maven/org.apache.tomcat:tomcat | >=4.1.0<=4.1.36 | |
maven/org.apache.tomcat:tomcat | >=5.0.0<=5.0.30 | |
maven/org.apache.tomcat:tomcat | >=5.5.0<=5.5.24 | |
maven/org.apache.tomcat:tomcat | >=6.0.0<=6.0.13 | |
Apache Tomcat | =3.3 | |
Apache Tomcat | =3.3.1 | |
Apache Tomcat | =3.3.1a | |
Apache Tomcat | =3.3.2 | |
Apache Tomcat | =4.1.0 | |
Apache Tomcat | =4.1.1 | |
Apache Tomcat | =4.1.2 | |
Apache Tomcat | =4.1.3 | |
Apache Tomcat | =4.1.3-beta | |
Apache Tomcat | =4.1.9-beta | |
Apache Tomcat | =4.1.10 | |
Apache Tomcat | =4.1.15 | |
Apache Tomcat | =4.1.24 | |
Apache Tomcat | =4.1.28 | |
Apache Tomcat | =4.1.31 | |
Apache Tomcat | =4.1.36 | |
Apache Tomcat | =5.0.0 | |
Apache Tomcat | =5.0.1 | |
Apache Tomcat | =5.0.2 | |
Apache Tomcat | =5.0.3 | |
Apache Tomcat | =5.0.4 | |
Apache Tomcat | =5.0.5 | |
Apache Tomcat | =5.0.6 | |
Apache Tomcat | =5.0.7 | |
Apache Tomcat | =5.0.8 | |
Apache Tomcat | =5.0.9 | |
Apache Tomcat | =5.0.10 | |
Apache Tomcat | =5.0.11 | |
Apache Tomcat | =5.0.12 | |
Apache Tomcat | =5.0.13 | |
Apache Tomcat | =5.0.14 | |
Apache Tomcat | =5.0.15 | |
Apache Tomcat | =5.0.16 | |
Apache Tomcat | =5.0.17 | |
Apache Tomcat | =5.0.18 | |
Apache Tomcat | =5.0.19 | |
Apache Tomcat | =5.0.21 | |
Apache Tomcat | =5.0.22 | |
Apache Tomcat | =5.0.23 | |
Apache Tomcat | =5.0.24 | |
Apache Tomcat | =5.0.25 | |
Apache Tomcat | =5.0.26 | |
Apache Tomcat | =5.0.27 | |
Apache Tomcat | =5.0.28 | |
Apache Tomcat | =5.0.29 | |
Apache Tomcat | =5.0.30 | |
Apache Tomcat | =5.5.0 | |
Apache Tomcat | =5.5.1 | |
Apache Tomcat | =5.5.2 | |
Apache Tomcat | =5.5.3 | |
Apache Tomcat | =5.5.4 | |
Apache Tomcat | =5.5.5 | |
Apache Tomcat | =5.5.6 | |
Apache Tomcat | =5.5.7 | |
Apache Tomcat | =5.5.8 | |
Apache Tomcat | =5.5.9 | |
Apache Tomcat | =5.5.10 | |
Apache Tomcat | =5.5.11 | |
Apache Tomcat | =5.5.12 | |
Apache Tomcat | =5.5.13 | |
Apache Tomcat | =5.5.14 | |
Apache Tomcat | =5.5.15 | |
Apache Tomcat | =5.5.16 | |
Apache Tomcat | =5.5.17 | |
Apache Tomcat | =5.5.18 | |
Apache Tomcat | =5.5.19 | |
Apache Tomcat | =5.5.20 | |
Apache Tomcat | =5.5.21 | |
Apache Tomcat | =5.5.22 | |
Apache Tomcat | =5.5.23 | |
Apache Tomcat | =5.5.24 | |
Apache Tomcat | =6.0.0 | |
Apache Tomcat | =6.0.1 | |
Apache Tomcat | =6.0.2 | |
Apache Tomcat | =6.0.3 | |
Apache Tomcat | =6.0.4 | |
Apache Tomcat | =6.0.5 | |
Apache Tomcat | =6.0.6 | |
Apache Tomcat | =6.0.7 | |
Apache Tomcat | =6.0.8 | |
Apache Tomcat | =6.0.9 | |
Apache Tomcat | =6.0.10 | |
Apache Tomcat | =6.0.11 | |
Apache Tomcat | =6.0.12 | |
Apache Tomcat | =6.0.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.