UBUNTU-CVE-2015-5346

See a problem?
Source
https://ubuntu.com/security/notices/UBUNTU-CVE-2015-5346
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2015/UBUNTU-CVE-2015-5346.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2015-5346
Related
Published
2016-02-24T00:00:00Z
Modified
2016-02-24T00:00:00Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.

References

Affected packages

Ubuntu:14.04:LTS / tomcat7

Package

Name
tomcat7
Purl
pkg:deb/ubuntu/tomcat7@7.0.52-1ubuntu0.6?arch=src?distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.0.52-1ubuntu0.6

Affected versions

7.*

7.0.42-1
7.0.47-1
7.0.50-1
7.0.52-1
7.0.52-1ubuntu0.1
7.0.52-1ubuntu0.3

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "low",
    "binaries": [
        {
            "tomcat7-examples": "7.0.52-1ubuntu0.6",
            "tomcat7-admin": "7.0.52-1ubuntu0.6",
            "tomcat7-user": "7.0.52-1ubuntu0.6",
            "libservlet3.0-java": "7.0.52-1ubuntu0.6",
            "libservlet3.0-java-doc": "7.0.52-1ubuntu0.6",
            "libtomcat7-java": "7.0.52-1ubuntu0.6",
            "tomcat7-docs": "7.0.52-1ubuntu0.6",
            "tomcat7": "7.0.52-1ubuntu0.6",
            "tomcat7-common": "7.0.52-1ubuntu0.6"
        }
    ]
}

Ubuntu:16.04:LTS / tomcat7

Package

Name
tomcat7
Purl
pkg:deb/ubuntu/tomcat7@7.0.68-1?arch=src?distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.0.68-1

Affected versions

7.*

7.0.64-1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "low",
    "binaries": [
        {
            "tomcat7-examples": "7.0.68-1",
            "tomcat7-admin": "7.0.68-1",
            "tomcat7-user": "7.0.68-1",
            "libservlet3.0-java": "7.0.68-1",
            "libservlet3.0-java-doc": "7.0.68-1",
            "libtomcat7-java": "7.0.68-1",
            "tomcat7-docs": "7.0.68-1",
            "tomcat7": "7.0.68-1",
            "tomcat7-common": "7.0.68-1"
        }
    ]
}

Ubuntu:16.04:LTS / tomcat8

Package

Name
tomcat8
Purl
pkg:deb/ubuntu/tomcat8@8.0.32-1ubuntu1?arch=src?distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.0.32-1ubuntu1

Affected versions

8.*

8.0.26-1
8.0.28-1
8.0.30-1
8.0.32-1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "low",
    "binaries": [
        {
            "tomcat8-common": "8.0.32-1ubuntu1",
            "tomcat8-admin": "8.0.32-1ubuntu1",
            "tomcat8-user": "8.0.32-1ubuntu1",
            "libtomcat8-java": "8.0.32-1ubuntu1",
            "tomcat8": "8.0.32-1ubuntu1",
            "tomcat8-examples": "8.0.32-1ubuntu1",
            "libservlet3.1-java-doc": "8.0.32-1ubuntu1",
            "libservlet3.1-java": "8.0.32-1ubuntu1",
            "tomcat8-docs": "8.0.32-1ubuntu1"
        }
    ]
}