6.8
CVSSv2

CVE-2013-2067

Published: 01/06/2013 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 up to and including 6.0.36 and 7.x prior to 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote malicious users to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache tomcat 6.0.33

apache tomcat 6.0.21

apache tomcat 6.0.31

apache tomcat 6.0.29

apache tomcat 6.0.24

apache tomcat 6.0.32

apache tomcat 6.0.28

apache tomcat 6.0.30

apache tomcat 6.0.26

apache tomcat 6.0.27

apache tomcat 6.0.35

apache tomcat 6.0.36

apache tomcat 7.0.2

apache tomcat 7.0.12

apache tomcat 7.0.20

apache tomcat 7.0.8

apache tomcat 7.0.1

apache tomcat 7.0.5

apache tomcat 7.0.4

apache tomcat 7.0.22

apache tomcat 7.0.28

apache tomcat 7.0.0

apache tomcat 7.0.6

apache tomcat 7.0.18

apache tomcat 7.0.14

apache tomcat 7.0.11

apache tomcat 7.0.23

apache tomcat 7.0.7

apache tomcat 7.0.13

apache tomcat 7.0.30

apache tomcat 7.0.15

apache tomcat 7.0.19

apache tomcat 7.0.16

apache tomcat 7.0.10

apache tomcat 7.0.25

apache tomcat 7.0.32

apache tomcat 7.0.21

apache tomcat 7.0.17

apache tomcat 7.0.9

apache tomcat 7.0.3

Vendor Advisories

Several security issues were fixed in Tomcat ...
Debian Bug report logs - #707704 tomcat7: CVE-2013-2071 Package: tomcat7; Maintainer for tomcat7 is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Source for tomcat7 is src:tomcat7 (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Fri, 10 May 2013 13:27:01 UTC Seve ...
Multiple security issues were found in the Tomcat servlet and JSP engine: CVE-2013-2067 FORM authentication associates the most recent request requiring authentication with the current session By repeatedly sending a request for an authenticated resource while the victim is completing the login form, an attacker could inject a req ...
java/org/apache/catalina/authenticator/FormAuthenticatorjava in the form authentication feature in Apache Tomcat 6021 through 6036 and 7x before 7033 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during com ...

References

CWE-287http://svn.apache.org/viewvc/tomcat/tc6.0.x/trunk/java/org/apache/catalina/authenticator/FormAuthenticator.java?r1=1417891&r2=1417890&pathrev=1417891http://svn.apache.org/viewvc?view=revision&revision=1417891http://svn.apache.org/viewvc/tomcat/tc7.0.x/trunk/java/org/apache/catalina/authenticator/FormAuthenticator.java?r1=1408044&r2=1408043&pathrev=1408044http://tomcat.apache.org/security-6.htmlhttp://tomcat.apache.org/security-7.htmlhttp://svn.apache.org/viewvc?view=revision&revision=1408044http://www.ubuntu.com/usn/USN-1841-1http://rhn.redhat.com/errata/RHSA-2013-0964.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0839.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1437.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0834.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0833.htmlhttp://archives.neohapsis.com/archives/bugtraq/2013-05/0041.htmlhttp://www.securityfocus.com/bid/64758http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.securityfocus.com/bid/59799https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b%40%3Cdev.tomcat.apache.org%3Ehttps://usn.ubuntu.com/1841-1/https://nvd.nist.govhttps://access.redhat.com/security/cve/cve-2013-2067