Vulnerabilidad en javaorgapachecatalinaauthenticatorFormAuthenticator.java en la autenticación en Apache Tomcat (CVE-2013-2067)
Gravedad CVSS v2.0:
MEDIA
Tipo:
CWE-287
Autenticación incorrecta
Fecha de publicación:
01/06/2013
Última modificación:
11/04/2025
Descripción
v6.0.21 hasta v6.0.36 y v7.x anteriores a v7.0.33 no maneja de forma adecuada las relaciones entre requisitos de autenticación y las sesiones, lo que permite a atacantes remotos a inyctar una petición en una sesión enviando esta petición durante el proceso de completado del formulario de login, es una variante del ataque de fijado de sesión.
Impacto
Puntuación base 2.0
6.80
Gravedad 2.0
MEDIA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:a:apache:tomcat:6.0.21:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:tomcat:6.0.24:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:tomcat:6.0.26:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:tomcat:6.0.27:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:tomcat:6.0.28:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:tomcat:6.0.29:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:tomcat:6.0.30:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:tomcat:6.0.31:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:tomcat:6.0.32:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:tomcat:6.0.33:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:tomcat:6.0.35:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:tomcat:6.0.36:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:tomcat:7.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:tomcat:7.0.0:beta:*:*:*:*:*:* | ||
| cpe:2.3:a:apache:tomcat:7.0.1:*:*:*:*:*:*:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- http://archives.neohapsis.com/archives/bugtraq/2013-05/0041.html
- http://rhn.redhat.com/errata/RHSA-2013-0833.html
- http://rhn.redhat.com/errata/RHSA-2013-0834.html
- http://rhn.redhat.com/errata/RHSA-2013-0839.html
- http://rhn.redhat.com/errata/RHSA-2013-0964.html
- http://rhn.redhat.com/errata/RHSA-2013-1437.html
- http://svn.apache.org/viewvc/tomcat/tc6.0.x/trunk/java/org/apache/catalina/authenticator/FormAuthenticator.java?r1=1417891&r2=1417890&pathrev=1417891
- http://svn.apache.org/viewvc/tomcat/tc7.0.x/trunk/java/org/apache/catalina/authenticator/FormAuthenticator.java?r1=1408044&r2=1408043&pathrev=1408044
- http://svn.apache.org/viewvc?view=revision&revision=1408044
- http://svn.apache.org/viewvc?view=revision&revision=1417891
- http://tomcat.apache.org/security-6.html
- http://tomcat.apache.org/security-7.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/59799
- http://www.securityfocus.com/bid/64758
- http://www.ubuntu.com/usn/USN-1841-1
- https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b%40%3Cdev.tomcat.apache.org%3E
- http://archives.neohapsis.com/archives/bugtraq/2013-05/0041.html
- http://rhn.redhat.com/errata/RHSA-2013-0833.html
- http://rhn.redhat.com/errata/RHSA-2013-0834.html
- http://rhn.redhat.com/errata/RHSA-2013-0839.html
- http://rhn.redhat.com/errata/RHSA-2013-0964.html
- http://rhn.redhat.com/errata/RHSA-2013-1437.html
- http://svn.apache.org/viewvc/tomcat/tc6.0.x/trunk/java/org/apache/catalina/authenticator/FormAuthenticator.java?r1=1417891&r2=1417890&pathrev=1417891
- http://svn.apache.org/viewvc/tomcat/tc7.0.x/trunk/java/org/apache/catalina/authenticator/FormAuthenticator.java?r1=1408044&r2=1408043&pathrev=1408044
- http://svn.apache.org/viewvc?view=revision&revision=1408044
- http://svn.apache.org/viewvc?view=revision&revision=1417891
- http://tomcat.apache.org/security-6.html
- http://tomcat.apache.org/security-7.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.securityfocus.com/bid/59799
- http://www.securityfocus.com/bid/64758
- http://www.ubuntu.com/usn/USN-1841-1
- https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b%40%3Cdev.tomcat.apache.org%3E



