PT-2010-5415 · Apache · Apache Tomcat
Published
2010-11-26
·
Updated
2022-05-14
·
CVE-2010-4312
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Apache Tomcat versions 6.x
Description
The default configuration of Apache Tomcat does not include the HTTPOnly flag in a Set-Cookie header. This makes it easier for remote attackers to hijack a session via script access to a cookie.
Recommendations
For Apache Tomcat version 6.x, consider configuring the Set-Cookie header to include the HTTPOnly flag to prevent session hijacking.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Tomcat