PT-2010-5415 · Apache · Apache Tomcat

Published

2010-11-26

·

Updated

2022-05-14

·

CVE-2010-4312

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 6.x
Description The default configuration of Apache Tomcat does not include the HTTPOnly flag in a Set-Cookie header. This makes it easier for remote attackers to hijack a session via script access to a cookie.
Recommendations For Apache Tomcat version 6.x, consider configuring the Set-Cookie header to include the HTTPOnly flag to prevent session hijacking.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-4312
GHSA-PVJH-7H8Q-Q56R

Affected Products

Apache Tomcat