CVE-2013-2067

CVSS V2 Medium 6.8 CVSS V3 None
Description
java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.
Overview
  • CVE ID
  • CVE-2013-2067
  • Assigner
  • secalert@redhat.com
  • Vulnerability Status
  • Modified
  • Published Version
  • 2013-06-01T14:21:05
  • Last Modified Date
  • 2019-04-15T16:29:19
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:apache:tomcat:6.0.21:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:6.0.24:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:6.0.26:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:6.0.27:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:6.0.28:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:6.0.29:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:6.0.30:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:6.0.31:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:6.0.32:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:6.0.33:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:6.0.35:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:6.0.36:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:7.0.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:7.0.0:beta:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:7.0.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:7.0.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:7.0.2:beta:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:7.0.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:7.0.4:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:7.0.4:beta:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:7.0.5:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:7.0.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:7.0.7:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:7.0.8:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:7.0.9:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:7.0.10:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:7.0.11:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:7.0.12:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:7.0.13:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:7.0.14:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:7.0.15:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:7.0.16:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:7.0.17:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:7.0.18:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:7.0.19:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:7.0.20:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:7.0.21:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:7.0.22:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:7.0.23:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:7.0.25:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:7.0.28:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:7.0.30:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:tomcat:7.0.32:*:*:*:*:*:*:* 1 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:M/Au:N/C:P/I:P/A:P
  • Access Vector
  • NETWORK
  • Access Compatibility
  • MEDIUM
  • Authentication
  • NONE
  • Confidentiality Impact
  • PARTIAL
  • Integrity Impact
  • PARTIAL
  • Availability Impact
  • PARTIAL
  • Base Score
  • 6.8
  • Severity
  • MEDIUM
  • Exploitability Score
  • 8.6
  • Impact Score
  • 6.4
References
Reference URL Reference Tags
http://svn.apache.org/viewvc/tomcat/tc6.0.x/trunk/java/org/apache/catalina/authenticator/FormAuthenticator.java?r1=1417891&r2=1417890&pathrev=1417891 Patch
http://svn.apache.org/viewvc?view=revision&revision=1417891 Patch
http://svn.apache.org/viewvc/tomcat/tc7.0.x/trunk/java/org/apache/catalina/authenticator/FormAuthenticator.java?r1=1408044&r2=1408043&pathrev=1408044 Patch
http://tomcat.apache.org/security-6.html Vendor Advisory
http://tomcat.apache.org/security-7.html Vendor Advisory
http://svn.apache.org/viewvc?view=revision&revision=1408044 Patch
http://www.ubuntu.com/usn/USN-1841-1
http://rhn.redhat.com/errata/RHSA-2013-0964.html
http://rhn.redhat.com/errata/RHSA-2013-0839.html
http://rhn.redhat.com/errata/RHSA-2013-1437.html
http://rhn.redhat.com/errata/RHSA-2013-0834.html
http://rhn.redhat.com/errata/RHSA-2013-0833.html
http://archives.neohapsis.com/archives/bugtraq/2013-05/0041.html
http://www.securityfocus.com/bid/64758
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
http://www.securityfocus.com/bid/59799
https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb@%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b@%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113@%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95@%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c@%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b@%3Cdev.tomcat.apache.org%3E
History
Created Old Value New Value Data Type Notes
2022-05-10 17:43:53 Added to TrackCVE
2022-12-01 18:39:56 2013-06-01T14:21Z 2013-06-01T14:21:05 CVE Published Date updated
2022-12-01 18:39:56 2019-04-15T16:29:19 CVE Modified Date updated
2022-12-01 18:39:56 Modified Vulnerability Status updated