Description
When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2077-1 | tomcat7 security update |
Debian DLA |
DLA-2209-1 | tomcat8 security update |
Debian DSA |
DSA-4596-1 | tomcat8 security update |
Debian DSA |
DSA-4680-1 | tomcat9 security update |
EUVD |
EUVD-2019-0787 | When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability. |
Github GHSA |
GHSA-9xcj-c8cr-8c3c | In Apache Tomcat, when using FORM authentication there was a narrow window where an attacker could perform a session fixation attack |
Ubuntu USN |
USN-4251-1 | Tomcat vulnerabilities |
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Subscriptions
Apache
Subscribe
Tomcat
Subscribe
Canonical
Subscribe
Ubuntu Linux
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Opensuse
Subscribe
Leap
Subscribe
Oracle
Subscribe
Agile Engineering Data Management
Subscribe
Hyperion Infrastructure Technology
Subscribe
Instantis Enterprisetrack
Subscribe
Micros Relate Crm Software
Subscribe
Mysql Enterprise Monitor
Subscribe
Retail Order Broker
Subscribe
Transportation Management
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Jboss Enterprise Web Server
Subscribe
Rhel Eus
Subscribe
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-05T01:40:15.805Z
Reserved: 2019-10-14T00:00:00.000Z
Link: CVE-2019-17563
No data.
Status : Modified
Published: 2019-12-23T17:15:11.803
Modified: 2024-11-21T04:32:32.160
Link: CVE-2019-17563
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN