CVE-2007-5333

Aliases:GHSA-cww4-vj5r-rx57
Modified
Published: 12 Feb 2008, 00:00
Last modified:07 Aug 2024, 15:24

Vulnerability Summary

Overall Risk (default)
medium
46/100
CVSS Score
5 MEDIUM
v2.0 (nvd)
EPSS Score
81.6% CRITICAL
82% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
2 found
Dark Web
Not detected

Timeline

12 Feb 2008, 00:00
Published
Vulnerability first disclosed
07 Aug 2024, 15:24
Last Modified
Vulnerability information updated

Description

Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double quote (") characters or (2) %5C (encoded backslash) sequences in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks. NOTE: this issue exists because of an incomplete fix for CVE-2007-3385.

CVSS Metrics

  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 81.60% Percentile: 99%

Techniques & Countermeasures

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Affected Systems

  • UnknownTomcat

    ≥ 4.1.0, ≤ 4.1.36 | ≥ 5.5.0, ≤ 5.5.25 | ≥ 6.0.0, ≤ 6.0.14

  • org.apache.tomcattomcat

    ≥ 6.0.0, < 6.0.15 | ≥ 5.5.0, < 5.5.26 | ≥ 4.1.0, < 4.1.37

References (64)