CVE-2008-0128

Loading...

General

Score:5.0/10.0
Severity:Medium
Category:Configuration Error
Exploit:Available

Impact Metrics

Confidentiality:Partial
Integrity:None
Availability:None

Exploitability Metrics

Access Vector:Network
Access Complexity:Low
Authentication:None

Relative vulnerabilities

CVE-2004-0687, CVE-2004-0688, CVE-2004-0885, CVE-2004-0914, CVE-2005-0605, CVE-2005-2090, CVE-2005-3510, CVE-2005-3964, CVE-2005-4838, CVE-2006-0254, CVE-2006-0898, CVE-2006-1329, CVE-2006-3835, CVE-2006-3918, CVE-2006-5752, CVE-2006-7195, CVE-2006-7196, CVE-2006-7197, CVE-2007-0243, CVE-2007-0450, CVE-2007-1349, CVE-2007-1355, CVE-2007-1358, CVE-2007-1858, CVE-2007-1860, CVE-2007-1863, CVE-2007-2435, CVE-2007-2449, CVE-2007-2450, CVE-2007-2788, CVE-2007-2789, CVE-2007-3304, CVE-2007-3382, CVE-2007-3385, CVE-2007-3847, CVE-2007-4465, CVE-2007-5000, CVE-2007-5116, CVE-2007-5333, CVE-2007-5461, CVE-2007-5961, CVE-2007-6306, CVE-2007-6388, CVE-2008-0005, CVE-2008-1232, CVE-2008-1927, CVE-2008-2364, CVE-2008-2369, CVE-2008-2370, CVE-2008-2938, CVE-2008-2939, CVE-2008-5515, CVE-2009-0023, CVE-2009-0033, CVE-2009-0580, CVE-2009-1891, CVE-2009-1955, CVE-2009-1956, CVE-2009-2412, CVE-2009-3094, CVE-2009-3095, CVE-2009-4901, CVE-2009-4902, CVE-2010-0407, CVE-2010-0434

Published on 23/01/08 - Updated on 25/03/19

Description

The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

Category: Configuration Error

CWE-16 (Configuration)
Weaknesses in this category are typically introduced during the configuration of the software.

Security Notices

US National Vulnerability DatabaseCVE-2008-0128
Agence Nationale de la Sécurité des Systèmes d'Information CERTA-2009-AVI-032
Redhat RHSA-2008:0261, RHSA-2008:0524, RHSA-2008:0630, RHSA-2010:0602
Renater 2010/VULN248

Exploits

SecurityFocusBID-27365

Relative technologies

VendorProduct
apachetomcat

Share this vulnerability with:

Twitter Facebook LinkedIn Mail