CVE-2007-5333
Exposure of Sensitive Information in Apache Tomcat
EPSS 62.6%
描述
Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double quote (") characters or (2) %5C (encoded backslash) sequences in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks. NOTE: this issue exists because of an incomplete fix for CVE-2007-3385.
如何修補 CVE-2007-5333
要修補 CVE-2007-5333,請將受影響套件升級到下列已修補版本。
- Maven/org.apache.tomcat:tomcat—升級至 6.0.15 或更新版本
CVE-2007-5333 正在被利用嗎?
可能 — EPSS 為 62.6%,屬於高被利用機率區間,建議優先修補。
受影響套件(1)
- >= 6.0.0, < 6.0.15