PT-2013-3524 · Apache+2 · Apache Tomcat+2

Publicado

2013-05-03

·

Atualizado

2022-05-14

·

CVE-2013-2067

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 6.0.21 through 6.0.36 Apache Tomcat versions 7.x before 7.0.33
Description The form authentication feature in Apache Tomcat does not properly handle the relationships between authentication requirements and sessions. This allows remote attackers to inject a request into a session by sending the request during completion of the login form, which is a variant of a session fixation attack. Specifically, the FORM authentication associates the most recent request requiring authentication with the current session. By repeatedly sending a request for an authenticated resource while the victim is completing the login form, an attacker could inject a request that would be executed using the victim's credentials.
Recommendations For Apache Tomcat versions 6.0.21 through 6.0.36, update to a version after 6.0.36 to resolve the issue. For Apache Tomcat versions 7.x before 7.0.33, update to version 7.0.33 or later to resolve the issue. As a temporary workaround, consider restricting access to authenticated resources to minimize the risk of exploitation.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CESA-2013_0964
CVE-2013-2067
DSA-2725-1
DSA-2897-1
GHSA-6M48-JXWX-76Q7
MGASA-2014-0082
RHSA-2013:0834
RHSA-2013:0839
RHSA-2013:0964
RHSA-2013:1011
RHSA-2013:1012
RHSA-2013_0964
USN-1841-1

Produtos afetados

Apache Tomcat
Centos
Red Hat