CVE-2010-4312

EPSS 1.7%

Apache Tomcat has cookies without HTTPOnly flag in Set-Cookie header

Published: 5/14/2022Modified: 2/8/2024

Description

The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script access to a cookie.

Affected packages (1)

References (6)