4.3

CVE-2007-3385

Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 does not properly handle the \" character sequence in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheTomcat Version3.3
ApacheTomcat Version3.3.1
ApacheTomcat Version3.3.1a
ApacheTomcat Version3.3.2
ApacheTomcat Version4.1.0
ApacheTomcat Version4.1.1
ApacheTomcat Version4.1.2
ApacheTomcat Version4.1.3
ApacheTomcat Version4.1.3 Updatebeta
ApacheTomcat Version4.1.9 Updatebeta
ApacheTomcat Version4.1.10
ApacheTomcat Version4.1.15
ApacheTomcat Version4.1.24
ApacheTomcat Version4.1.28
ApacheTomcat Version4.1.31
ApacheTomcat Version4.1.36
ApacheTomcat Version5.0.0
ApacheTomcat Version5.0.1
ApacheTomcat Version5.0.2
ApacheTomcat Version5.0.3
ApacheTomcat Version5.0.4
ApacheTomcat Version5.0.5
ApacheTomcat Version5.0.6
ApacheTomcat Version5.0.7
ApacheTomcat Version5.0.8
ApacheTomcat Version5.0.9
ApacheTomcat Version5.0.10
ApacheTomcat Version5.0.11
ApacheTomcat Version5.0.12
ApacheTomcat Version5.0.13
ApacheTomcat Version5.0.14
ApacheTomcat Version5.0.15
ApacheTomcat Version5.0.16
ApacheTomcat Version5.0.17
ApacheTomcat Version5.0.18
ApacheTomcat Version5.0.19
ApacheTomcat Version5.0.21
ApacheTomcat Version5.0.22
ApacheTomcat Version5.0.23
ApacheTomcat Version5.0.24
ApacheTomcat Version5.0.25
ApacheTomcat Version5.0.26
ApacheTomcat Version5.0.27
ApacheTomcat Version5.0.28
ApacheTomcat Version5.0.29
ApacheTomcat Version5.0.30
ApacheTomcat Version5.5.0
ApacheTomcat Version5.5.1
ApacheTomcat Version5.5.2
ApacheTomcat Version5.5.3
ApacheTomcat Version5.5.4
ApacheTomcat Version5.5.5
ApacheTomcat Version5.5.6
ApacheTomcat Version5.5.7
ApacheTomcat Version5.5.8
ApacheTomcat Version5.5.9
ApacheTomcat Version5.5.10
ApacheTomcat Version5.5.11
ApacheTomcat Version5.5.12
ApacheTomcat Version5.5.13
ApacheTomcat Version5.5.14
ApacheTomcat Version5.5.15
ApacheTomcat Version5.5.16
ApacheTomcat Version5.5.17
ApacheTomcat Version5.5.18
ApacheTomcat Version5.5.19
ApacheTomcat Version5.5.20
ApacheTomcat Version5.5.21
ApacheTomcat Version5.5.22
ApacheTomcat Version5.5.23
ApacheTomcat Version5.5.24
ApacheTomcat Version6.0.0
ApacheTomcat Version6.0.1
ApacheTomcat Version6.0.2
ApacheTomcat Version6.0.3
ApacheTomcat Version6.0.4
ApacheTomcat Version6.0.5
ApacheTomcat Version6.0.6
ApacheTomcat Version6.0.7
ApacheTomcat Version6.0.8
ApacheTomcat Version6.0.9
ApacheTomcat Version6.0.10
ApacheTomcat Version6.0.11
ApacheTomcat Version6.0.12
ApacheTomcat Version6.0.13
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 65.35% 0.984
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://www.kb.cert.org/vuls/id/993544
Patch
US Government Resource