PT-2013-3524 · Apache+2 · Apache Tomcat+2

Published

2013-05-03

·

Updated

2022-05-14

·

CVE-2013-2067

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 6.0.21 through 6.0.36 Apache Tomcat versions 7.x before 7.0.33
Description The form authentication feature in Apache Tomcat does not properly handle the relationships between authentication requirements and sessions. This allows remote attackers to inject a request into a session by sending the request during completion of the login form, which is a variant of a session fixation attack. Specifically, the FORM authentication associates the most recent request requiring authentication with the current session. By repeatedly sending a request for an authenticated resource while the victim is completing the login form, an attacker could inject a request that would be executed using the victim's credentials.
Recommendations For Apache Tomcat versions 6.0.21 through 6.0.36, update to a version after 6.0.36 to resolve the issue. For Apache Tomcat versions 7.x before 7.0.33, update to version 7.0.33 or later to resolve the issue. As a temporary workaround, consider restricting access to authenticated resources to minimize the risk of exploitation.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2013_0964
CVE-2013-2067
DSA-2725-1
DSA-2897-1
GHSA-6M48-JXWX-76Q7
MGASA-2014-0082
RHSA-2013:0834
RHSA-2013:0839
RHSA-2013:0964
RHSA-2013:1011
RHSA-2013:1012
RHSA-2013_0964
USN-1841-1

Affected Products

Apache Tomcat
Centos
Red Hat