Information Exposure Affecting org.apache.tomcat.embed:tomcat-embed-core package, versions [7.0.0,7.0.66) [8.0.0-RC1,8.0.30) [9.0.0.M1,9.0.0.M2)
Threat Intelligence
EPSS
0.94% (84th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JAVA-ORGAPACHETOMCATEMBED-30985
- published 22 Feb 2016
- disclosed 22 Feb 2016
- credit Unknown
Introduced: 22 Feb 2016
CVE-2015-5346 Open this link in a new tabOverview
org.apache.tomcat.embed:tomcat-embed-core
Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.
References
CVSS Scores
version 3.1