Apache Tomcat
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*, +1 more
- >= 11.0.0-M1, <= 11.0.7
- >= 10.1.0-M1, <= 10.1.41
- >= 9.0.0.M1, <= 9.0.105
A session fixation vulnerability has been identified in Apache Tomcat versions 11.0.0-M1 through 11.0.7, 10.1.0-M1 through 10.1.41, and 9.0.0.M1 through 9.0.105. Older, end-of-life versions may also be affected. When the rewrite valve was enabled for a web application, an attacker could craft a URL that, if clicked by a victim, would result in the victim's session being hijacked and their interactions with the resource being conducted under the attacker's session.
Exploitation of this vulnerability allows for session fixation, where an attacker can hijack a user's session and interact with resources on their behalf.
Users are advised to upgrade to Apache Tomcat 11.0.8, 10.1.42, or 9.0.106.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.