Apache Tomcat CVE-2013-2067 Session Fixation Vulnerability
BID:59799
Info
Apache Tomcat CVE-2013-2067 Session Fixation Vulnerability
| Bugtraq ID: | 59799 |
| Class: | Unknown |
| CVE: |
CVE-2013-2067 |
| Remote: | Yes |
| Local: | No |
| Published: | May 10 2013 12:00AM |
| Updated: | May 23 2017 04:26PM |
| Credit: | Apache Tomcat Security Team |
| Vulnerable: |
Ubuntu Ubuntu Linux 13.04 Ubuntu Ubuntu Linux 12.10 Ubuntu Ubuntu Linux 12.04 LTS Ubuntu Ubuntu Linux 10.04 LTS Redhat JBoss Portal 6.0.0 Redhat JBoss Enterprise Web Server 2.0.0 Redhat Enterprise Linux Workstation Optional 6 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server Optional 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node Optional 6 Redhat Enterprise Linux Desktop Optional 6 Oracle Transportation Management 6.3.2 Oracle Transportation Management 6.3.1 Oracle Transportation Management 6.3 Oracle Solaris 11.1 Oracle Oracle Transportation Management 6.2 Oracle Oracle Transportation Management 6.1 Oracle Oracle Transportation Management 6.0 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Oracle Communications Policy Management 12.1.1 Oracle Communications Policy Management 10.4.1 Oracle Communications Policy Management 9.9.1 Oracle Communications Policy Management 9.7.3 McAfee ePO-MVT 1.0.7 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 HP Service Manager 9.33 HP Service Manager 9.32 HP Service Manager 9.31 HP Service Manager 7.11 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 CTERA Networks CTERA Portal 3.1 CentOS CentOS 6 Avaya Voice Portal 5.1.3 Avaya Meeting Exchange 6.2 Avaya Aura Utility Services 6.2 Avaya Aura System Platform 6.2.1 Avaya Aura System Platform 6.0.2 Avaya Aura System Platform 6.0.1 Avaya Aura System Platform 6.3 Avaya Aura System Platform 6.2.1.0.9 Avaya Aura System Platform 6.2 SP1 Avaya Aura System Platform 6.2 Avaya Aura System Platform 6.0.3.9.3 Avaya Aura System Platform 6.0.3.8.3 Avaya Aura System Platform 6.0.3.0.3 Avaya Aura System Platform 6.0 SP3 Avaya Aura System Platform 6.0 SP2 Avaya Aura System Platform 6.0 Avaya Aura Presence Services 6.1.2 Avaya Aura Presence Services 6.1.1 Avaya Aura Presence Services 6.2 Avaya Aura Presence Services 6.1 SP2 Avaya Aura Presence Services 6.1 SP1 Avaya Aura Presence Services 6.1 Avaya Aura Presence Services 6.0 Avaya Aura Messaging 6.2 Avaya Aura Experience Portal 6.0.2 Avaya Aura Experience Portal 6.0.1 Avaya Aura Experience Portal 6.0 SP2 Avaya Aura Experience Portal 6.0 SP1 Avaya Aura Experience Portal 6.0 Avaya Aura Conferencing 7.0 Avaya Aura Application Server 5300 SIP Core 2.1 Avaya Aura Application Server 5300 SIP Core 2.0 PB28 Avaya Aura Application Server 5300 SIP Core 2.0 PB26 Avaya Aura Application Server 5300 SIP Core 2.0 PB25 Avaya Aura Application Server 5300 SIP Core 2.0 PB23 Avaya Aura Application Server 5300 SIP Core 2.0 PB19 Avaya Aura Application Server 5300 SIP Core 2.0 PB16 Avaya Aura Application Server 5300 SIP Core 2.0 Avaya Aura Application Enablement Services 6.2 Avaya Aura Application Enablement Services 6.1.2 Avaya Aura Application Enablement Services 6.1.1 Avaya Aura Application Enablement Services 6.1 Avaya Aura Application Enablement Services 6.0 Apache Tomcat 7.0.32 Apache Tomcat 7.0.31 Apache Tomcat 7.0.30 Apache Tomcat 7.0.29 Apache Tomcat 7.0.28 Apache Tomcat 7.0.27 Apache Tomcat 7.0.26 Apache Tomcat 7.0.25 Apache Tomcat 7.0.24 Apache Tomcat 7.0.23 Apache Tomcat 7.0.16 Apache Tomcat 7.0.14 Apache Tomcat 7.0.13 Apache Tomcat 7.0.12 Apache Tomcat 7.0.9 Apache Tomcat 7.0.8 Apache Tomcat 7.0.7 Apache Tomcat 7.0.6 Apache Tomcat 7.0.4 Apache Tomcat 7.0.3 Apache Tomcat 7.0.2 Apache Tomcat 7.0.1 Apache Tomcat 7.0 Apache Tomcat 6.0.36 Apache Tomcat 6.0.35 Apache Tomcat 6.0.28 Apache Tomcat 6.0.27 Apache Tomcat 6.0.26 Apache Tomcat 6.0.25 Apache Tomcat 6.0.24 Apache Tomcat 6.0.20 Apache Tomcat 6.0.18 Apache Tomcat 6.0.17 Apache Tomcat 6.0.16 Apache Tomcat 6.0.15 Apache Tomcat 6.0.14 Apache Tomcat 6.0.13 Apache Tomcat 6.0.12 Apache Tomcat 6.0.11 Apache Tomcat 6.0.10 Apache Tomcat 6.0.9 Apache Tomcat 6.0.8 Apache Tomcat 6.0.7 Apache Tomcat 6.0.6 Apache Tomcat 6.0.5 Apache Tomcat 6.0.4 Apache Tomcat 6.0.3 Apache Tomcat 6.0.2 Apache Tomcat 6.0.1 Apache Tomcat 6.0 Apache Tomcat 7.0.5 Apache Tomcat 7.0.40 Apache Tomcat 7.0.22 Apache Tomcat 7.0.21 Apache Tomcat 7.0.20 Apache Tomcat 7.0.19 Apache Tomcat 7.0.18 Apache Tomcat 7.0.11 Apache Tomcat 7.0.10 Apache Tomcat 6.0.33 Apache Tomcat 6.0.32 Apache Tomcat 6.0.31 Apache Tomcat 6.0.30 Apache Tomcat 6.0.29 Apache Tomcat 6.0.19 |
| Not Vulnerable: |
Redhat JBoss Portal 6.1 Redhat JBoss Enterprise Web Server 2.0.1 Oracle Solaris 11.1.11.4.0 HP Service Manager 9.33.0035 CTERA Networks CTERA Portal 3.2.28 CTERA Networks CTERA Portal 3.1.39 Apache Tomcat 7.0.33 Apache Tomcat 6.0.37 |
Discussion
Apache Tomcat CVE-2013-2067 Session Fixation Vulnerability
Apache Tomcat is prone to a session-fixation vulnerability.
An attacker can exploit this issue to hijack an arbitrary session and gain unauthorized access to the affected application.
The following versions are vulnerable:
Tomcat 7.0.0 through 7.0.32
Tomcat 6.0.0 through 6.0.36
Apache Tomcat is prone to a session-fixation vulnerability.
An attacker can exploit this issue to hijack an arbitrary session and gain unauthorized access to the affected application.
The following versions are vulnerable:
Tomcat 7.0.0 through 7.0.32
Tomcat 6.0.0 through 6.0.36
Exploit / POC
Apache Tomcat CVE-2013-2067 Session Fixation Vulnerability
To exploit these issues an attacker entices an unsuspecting user into following a malicious URI.
To exploit these issues an attacker entices an unsuspecting user into following a malicious URI.
Solution / Fix
Apache Tomcat CVE-2013-2067 Session Fixation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache Tomcat CVE-2013-2067 Session Fixation Vulnerability
References:
References:
- Apache Tomcat Homepage (Apache)
- Apache Tomcat Session fixation with FORM authenticator (CVE-2013-2067) (Avaya)
- CVE-2013-2067 Session fixation with FORM authenticator (Full Disclosure)
- CVE-2013-2067: Fixed in Apache Tomcat 6.0.37 (Apache Software Foundation)
- CVE-2013-2067: Fixed in Apache Tomcat 7.0.33 (Apache Software Foundation)
- Multiple vulnerabilities in CTERA Portal (SEC Consult Vulnerability Lab)
- Multiple vulnerabilities in Tomcat (Oracle)
- Critical Patch Security Advisory - October 2016 (Oracle)
- HP Service Manager, Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF (HP)
- Important: Red Hat JBoss Portal 6.1.0 update (Red Hat)
- Oracle Critical Patch Update Advisory - January 2014 (Oracle)