Description
Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 does not properly handle the \" character sequence in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1447-1 | New tomcat5.5 packages fix several vulnerabilities |
Debian DSA |
DSA-1453-1 | New tomcat5 packages fix several vulnerabilities |
Github GHSA |
GHSA-6j8f-66vh-39mj | Apache Tomcat Mishandles Character Sequence in Cookies |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T14:14:12.922Z
Reserved: 2007-06-25T00:00:00.000Z
Link: CVE-2007-3385
No data.
Status : Modified
Published: 2007-08-14T22:17:00.000
Modified: 2026-06-16T22:41:53.590
Link: CVE-2007-3385
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Debian DSA
Github GHSA