CVE-2019-17563

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/12/2019
Last modified:
07/11/2023

Description

When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* 7.0.0 (including) 7.0.98 (including)
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* 8.5.0 (including) 8.5.49 (including)
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* 9.0.0 (including) 9.0.29 (including)
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.1.2.4:*:*:*:*:*:*:*
cpe:2.3:a:oracle:instantis_enterprisetrack:*:*:*:*:*:*:*:* 17.1 (including) 17.3 (including)
cpe:2.3:a:oracle:micros_relate_crm_software:11.4:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:* 4.0.11.5331 (including)
cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:* 8.0.0 (including) 8.0.18.1217 (including)
cpe:2.3:a:oracle:retail_order_broker:15.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools