CVE-2007-3382
tomcat5 - several vulnerabilities
EPSS 81.4%
Description
Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 treats single quotes (`'`) as delimiters in cookies, which might cause sensitive information such as session IDs to be leaked and allow remote attackers to conduct session hijacking attacks.
How to fix CVE-2007-3382
To remediate CVE-2007-3382, upgrade the affected package to a fixed version below.
- Debian/tomcat5—upgrade to 5.0.30-12etch1 or later
- Debian/tomcat5.5—upgrade to 5.5.20-2etch1 or later
- —no fix listed
Is CVE-2007-3382 being exploited?
Likely — EPSS is 81.4%, placing CVE-2007-3382 in the top tier of vulnerabilities by exploitation probability. Prioritise patching.
Affected packages (3)
- from 0, < 5.0.30-12etch1
- from 0, < 5.5.20-2etch1
- >= 6.0.0, <= 6.0.13