PT-2013-1681 · Red Hat+1 · Red Hat Jboss Web+1

Published

2013-10-28

·

Updated

2013-10-30

·

CVE-2012-4529

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Red Hat JBoss Web versions 7.1.x and earlier
Description The issue concerns the org.apache.catalina.connector.Response.encodeURL method. When the tracking mode is set to COOKIE, it sends the jsessionid in the URL of the first response of a session. This allows remote attackers to obtain the session id either via a man-in-the-middle attack or by reading a log.
Recommendations For Red Hat JBoss Web versions 7.1.x and earlier, consider configuring the tracking mode to avoid sending the jsessionid in the URL, or apply alternative security measures to protect session ids from being obtained by unauthorized parties. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2012-4529
RHSA-2013:0834
RHSA-2013:0839

Affected Products

Apache Catalina
Red Hat Jboss Web