CVE Published: 23/12/2019 |
CVE Updated: 05/08/2024 |
CVE Year: 2019 Source: apache |
Vendor: Apache Software Foundation |
Product: Apache Tomcat Status : PUBLISHED
CVE-2019-17563 Description
When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability.