CVE-2019-17563

EUVD-2019-0787
When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
Affected Products (NVD)
VendorProductVersion
apachetomcat
7.0.0 ≤
𝑥
≤ 7.0.98
apachetomcat
8.5.0 ≤
𝑥
≤ 8.5.49
apachetomcat
9.0.0 ≤
𝑥
≤ 9.0.29
debiandebian_linux
8.0
debiandebian_linux
9.0
debiandebian_linux
10.0
opensuseleap
15.1
canonicalubuntu_linux
16.04
oracleagile_engineering_data_management
6.2.1.0
oraclehyperion_infrastructure_technology
11.1.2.4
oracleinstantis_enterprisetrack
17.1 ≤
𝑥
≤ 17.3
oraclemicros_relate_crm_software
11.4
oraclemysql_enterprise_monitor
𝑥
≤ 4.0.11.5331
oraclemysql_enterprise_monitor
8.0.0 ≤
𝑥
≤ 8.0.18.1217
oracleretail_order_broker
15.0
oracletransportation_management
6.3.7
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
tomcat9
bookworm
9.0.70-2
fixed
bullseye
9.0.43-2~deb11u10
fixed
bullseye (security)
9.0.43-2~deb11u10
fixed
sid
9.0.95-1
fixed
stretch
ignored
trixie
9.0.95-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
tomcat7
bionic
needs-triage
disco
dne
eoan
dne
focal
dne
groovy
dne
hirsute
dne
impish
dne
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
noble
dne
trusty
needs-triage
xenial
needs-triage
tomcat8
bionic
needs-triage
disco
dne
eoan
dne
focal
dne
groovy
dne
hirsute
dne
impish
dne
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
noble
dne
trusty
dne
xenial
Fixed 8.0.32-1ubuntu1.11
released
tomcat9
bionic
needs-triage
disco
ignored
eoan
ignored
focal
not-affected
groovy
not-affected
hirsute
not-affected
impish
not-affected
jammy
not-affected
kinetic
not-affected
lunar
not-affected
mantic
not-affected
noble
not-affected
trusty
dne
xenial
dne
References